All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog.
check— add external-tools-release-tags-resolve gatehooks— add claude-md-size-guard and no-revert-guardcli— add defineHandoffCommand factory for ecosystem hand-off wrappersoptimize— write pnpm 11+ overrides to pnpm-workspace.yamlmcp— port socket-mcp standalone intosocket mcpsubcommandscan— add --exclude-paths flag for full Tier 1 exclusion (port of #1298) (#1306)scan— brotli-compress .socket.facts.json on upload (port of #1291) (#1305)- add xport lock-step manifest tooling (#1284)
- bootstrap @socketsecurity/lib + @socketregistry/packageurl-js + @sinclair/typebox via firewall-checked registry fetch (#1282)
claude— add public-surface-reminder + token-hygiene hooks (#1272)build— port scripts/build.mts to shared build-pipeline orchestrator (#1265)cli— machine-output mode — stream discipline, flag propagation, scrubber (#1234)organization— show quota usage, max, and refresh time (#1236)cli— rename --default-branch (scan create) to --make-default-branch; harden default-branch flags (#1230)- backport v1.x features and DRY out HTTP layer
ci— add updating skill and weekly-update workflowsea— bundle Python packages at build time for offline operationbuild— pre-install socketsecurity into bundled Python for SEAvfs— add opengrep, trivy, trufflehog, python to SEA VFS extractionsecurity— add SHA-256 verification for PyPI package downloadssecurity— add SHA-256 checksum verification for PyCLI (socketsecurity)build— add npm package integrity verificationbuild— inline all external tool checksums at build timedlx— add SHA256 checksum verification for Python and socket-patch downloadstui— add advanced iocraft components and styling featurestui— add comprehensive terminal UI property supportiocraft— add binary download mechanism from socket-btmiocraft— add author field to platform packagespublish— use 'pre' dist-tag for all pre-release packagesiocraft— use 'pre' dist-tag for pre-release versionsiocraft— add MIT LICENSE files to socketaddon packagesiocraft— add @socketaddon/iocraft v3.0.0-pre.0 package infrastructurepublish— make dry-run first option and default to truesocket— add bootstrap loader for @socketbin/* binariesscan— add --workspace flag to scan create command- BREAKING:
patch— migrate socket-patch to v2.0.0 Rust binary from GitHub releases socketbin— improve platform detection for binary packages- add musl/Alpine Linux support for binary packages
build-infra— add github-error-utils for transient error handlingcli— use process.smol.mount() for full VFS directory extraction- add dependency updates to quality-scan skill + update deps
cli— add GH_TOKEN as fallback for GitHub authenticationcli— add explicit sfw command for Socket Firewallcli— add explicit pycli command for Python CLI invocationpython— unify Python CLI spawning with SEA and DLX supportbuild— add npm package download utilities for VFS bundlingskills— add validation and chain-of-thought to quality-scanscan— add socket-basics integration utilitiesclaude— add quality-scan skill for comprehensive code analysisdeps— add @socketbin packages to update script- migrate patch command to @socketsecurity/socket-patch@1.2.0 (#1042)
- add E2E test sharding and misc fixes (#1022)
- add alpm and vscode ecosystems, add scan type constants
- set scanType to socket_tier1 when creating reachability full scans
- add --silence flag to
socket fix - add --reach-lazy-mode flag for reachability analysis
telemetry— adding initial telemetry functionality to the clici— add force rebuild option to all workflow_dispatch workflowscli— standardize .version tracking across all extract scriptssea— improve build cache management and add local development modeconfig— use EditableJson for non-destructive config savingscan— add --reach-use-only-pregenerated-sboms flagfix— add --fix-version flag to override Coana CLI versionfix— add --ecosystems flag and rename --limit to --pr-limitfix— add --all flag to process all vulnerabilitiesdebug— add API request/response logging via SDK hookscli— add --reach-debug flag to enable verbose logging in the reachability (Coana) CLIbuild— leverage socket-btm releases for pre-compiled assetsscan— add reachability concurrency and analysis splitting flagspip— add socket pip3 command with auto-detection and context passingerrors— improve 403 error messages with command-specific permission guidancedx— standardize check runner output formattingdx— add .nvmrc and minimal quick-start guide- BREAKING:
build— improve setup script flags and logging build— add dead code elimination plugincli— optimize development workflow with caching and improved docscli-with-sentry— add package structure and build configurationbootstrap— add SOCKET_CLI_LOCAL_PATH support for testingcli— add supporting filescli— add new commandssfw— add Socket Firewall package manager wrapperssmol-builder— add granular checkpoint system and refactor loggerbootstrap— add Brotli compression for all bootstrap variantssmol— implement binary caching to avoid recompilation on post-processing failuresdlx— implement unified manifest for packages and binariesgit-hooks— make security checks mandatory, lint/test optionalscripts— add file validation checksvalidate— add bundle dependencies validationvalidation— add guard against link: dependencies and remove from rootpreflight— add @cyclonedx/cdxgen to background downloadsnlp— add progressive enhancement with ONNX Runtime stubci— add quantization level option to WASM workflowmodels— add INT8 quantization option for AI model buildsworkflows— add toggleable checkboxes for all build workflowsinstall— enhance installer with Socket branding and better UX- re-enable ONNX Runtime and add INT4-quantized AI models
build— add dependency-aware caching and binary build scriptsnode-smol-builder— implement VM-based bootstrap loader for async support- enhance socket build script with spinners and structured logging
- add comprehensive build script for socket package
- add shimmer effect to bootstrap spinner
- add spinner to bootstrap loading with withSpinner
build— add --platform and --arch flags for consistencybuild— add parallel builds and consolidate build systembuild— add intelligent caching to build systembootstrap— add IPC handshake support for subprocess detectionspawn— implement system Node.js detection with whichdlx— unify .dlx-metadata.json schema across TypeScript and C++ci— auto-update socketbin versions in provenance workflowcli— enhance error handling with network diagnostics and timeout errorsbootstrap— build SEA bootstrap in build scriptbootstrap— add SEA bootstrap for minimal SEA binariescli,cli-with-sentry— add LICENSE and CHANGELOG.md to packagesbuild— copy logos and data to packages during buildci— add npm@latest for trusted publishing supportcli— temporarily disable ONNX Runtime integrationpython— add Python CLI version tracking to build configurationpublish— query npm registry for latest @socketbin/* versionspublish— use base version from package.json for datetime versioningcli— add custom ONNX Runtime build package following yoga patternbootstrap— restore logger with lazy initialization supportbuild— add comprehensive Unicode property transformationsbuild— auto-generate socketbin spec for cache keyscompress— add spec string embedding for socket-lib cache keyscompress— implement self-extracting binary architecturedebug— add detailed HTTP request logging for failed API callsbootstrap— add Unicode property escape transforms for --with-intl=noneci— use Alpine Docker container for smol musl buildsci— add Alpine (musl) platform support to SEA and smol buildsfix— integrate provider pattern into PR operationsgit— implement GitLab provider with MR operationsgit— implement GitHub provider with PR operationsgit— add provider infrastructure for GitHub/GitLab supportcli— add markdown utility functions for consistent output formattingcli— implement markdown output for fix and optimize commandsfix— add comprehensive PR management and trackingsocket-fix— add batch PR flag for future implementationsocket-fix— add persistent GHSA tracking to avoid duplicate fixessocket-fix— add PR lifecycle logging and superseded PR detectionsea— add network retry, integrity checks, and freshness validationcli— add SHA256 checksum generation for build integritybuild— add network retry utility with exponential backoffbuild— auto-build bootstrap package when missingbootstrap— add system node detection and forwarding controlbootstrap— add system node detection and forwarding controlbootstrap— create shared bootstrap package for npm and smol buildssocket— add comprehensive builtin module mapping for smolsocket— add dual bootstrap build for SEA and smolci— build socket package bootstrap before SEA and smol buildsci— add stripped binary cache checkpoint for smol buildsbuild-infra— add preflight-checks runner for DRY build validationbuild-infra— add script-runner utilities for DRY monorepo operationsbuilders— add platform/arch arguments and use socket-lib parseArgssocket— add esbuild-based bootstrap implementationself-update— improve package manager detection and error messages- add install.sh for Socket CLI installation
ci— unify caching strategy across all build workflowsci— cache ONNX Runtime intermediate build artifactsci— add GitHub Actions grouping to WASM and SEA workflowsci— add Ninja installation for smol buildsnode-smol— add GitHub Actions grouping for verbose build stepsci— add concurrency control to build workflowssbom-generator— add TypeScript SBOM generator packageci— reuse cached binaries from build-socketbin.ymlci— add cache restoration and fallback WASM buildsci— add @socketbin build workflow with cachingci— add WASM build workflow with caching- add WIN32 shell support and update build infrastructure
node-sea-builder— add hash-based caching for SEA binariesnode-smol-builder— add hash-based caching for build artifactscli-ai— throttle model update checks to once per 24 hourscli— add hash-based caching to extraction scriptsbuild-infra— add extraction-cache utility for hash-based cachingsocketbin-cli-ai— add model update notifier with user promptsocketbin-cli-ai— add checkpoint-based incremental buildssocketbin-cli-ai— add complete build system with INT4 quantizationsocketbin— add @socketbin/cli-ai package with compression strategye2e— add interactive prompts and cache support for smol/sea binariessmol— make binary compression default with opt-outbuild-infra— add automated tool installer for cross-platform buildsmonorepo— add pnpm workspace catalog for Socket dependenciesnode-smol-builder— implement patch analysis with build-infra helpersbuild-infra— add patch analysis and conflict detectionbuild-infra— add build logging and checkpoint helperse2e— add auto-build support for binary E2E testse2e— add npm scripts for testing different binary typese2e— add comprehensive binary test suite for JS, smol, and SEAe2e— add environment files for comprehensive E2E testingbuild— add automated build tools installationenv— add RUN_E2E_TESTS environment variabledlx— add testable binary resolution patternenv— add system and LOCAL_PATH env modules with live VITEST modeos— add platform detection utilities for socketbin packagesregistry— add npm registry utilities for package downloadsbuild— complete WASM package build scriptsbuild-infra— add build environment and Rust builder modulestests— add case-insensitive env Proxy for Windows compatibilityscripts— add monorepo-aware update, type, and test scriptsscripts— add monorepo-aware lint, fix, and check scriptsscripts— add monorepo utility helpersbuild— add platform-specific binary size optimizationsecurity— prevent SIGUSR1 debugger signal handlingpatch— add default subcommand handlerconstants— add barrel file and fix test importspatch— enable patch command and fix testsconfig— add shared configuration architecture for monorepo- add Intl polyfill stub modules for CLI
- auto-strip AI attribution from commit messages
- add JS-only fallback release workflow for socket CLI
- register console and ask commands
- add interactive console command with Ink-based TUI
- add ASCII header banner utility with CI/VITEST plain text support
- implement SDK v3 file validation callback
- complete monorepo enhancements with all optional improvements
- add cli-sentry target for future @socketsecurity/cli-with-sentry package
- add all platform targets to build command
- add JSON and Markdown output support for manifest commands
- enhance workflows with monorepo support and configurable options
- add pre-publish validation to publishing workflows Add comprehensive validation to all three publishing workflows to prevent publishing broken packages. Created validation script that checks: - Package.json required fields and validity - Dist directory structure and files - Binary files and permissions - Data files presence - Production dependencies (no devDependencies) - Git status and tags - CLI bundle size sanity checks Workflow changes: - provenance.yml: Added validation after each of 3 package builds - publish-socketbin.yml: Added validation before main package publish - release-sea.yml: Added binary validation before GitHub release upload This prevents broken packages from reaching npm and users.
- add version consistency check script Create check-version-consistency.mjs to validate version numbers across package.json files before publishing. This ensures all packages are published with consistent versions. The script: - Checks main package.json version matches expected version - Optionally checks SEA npm package version (with warnings) - Exits with code 1 if critical version mismatches found - Provides clear colored output for CI workflows Referenced by .github/workflows/publish-socketbin.yml
- add ask mode demo and silence semantic model messages Add demo-ask-mode.mjs script that showcases natural language query translation across 6 categories with ~20 example queries. Remove semantic model loading messages since the model is optional and pattern matching works perfectly without it. The messages were noisy and gave the impression something was broken when it's actually working as intended.
- add esbuild configuration for CLI build Add esbuild configuration to replace Rollup bundler: - esbuild.cli.config.mjs: main configuration with plugins for package resolution - esbuild.cli.build.mjs: build script wrapper - esbuild-inject-import-meta.js: import.meta.url polyfill for CommonJS output This addresses template literal corruption issues in large bundles (>9MB) that occurred with Rollup. esbuild handles template literals correctly and produces faster builds without corruption.
- add module registration for --import flag Replace deprecated --loader with modern --import + register() API for Node.js 18+
- integrate MiniLM inference into socket ask command Updates handle-ask to use custom MiniLMInference engine instead of transformers.js. Implements hybrid semantic matching with three-tier progressive enhancement: pattern matching → word overlap → ONNX. Changes: - Replace transformers.js with MiniLMInference - Update cosineSimilarity to work with Float32Array - Use embedded ONNX from external/onnx-sync.mjs - Graceful degradation when ONNX unavailable
- add MiniLM model download and embedding scripts Scripts to download MiniLM model assets and embed them as base64 JavaScript for bundling. Follows yoga-layout WASM embedding pattern. - download-minilm.mjs: Downloads tokenizer and quantized ONNX model - embed-minilm.mjs: Embeds model as base64 in external/minilm-sync.mjs
- add MiniLM inference engine for semantic matching Implements direct ONNX Runtime integration with MiniLM model for semantic text understanding. Provides WordPiece tokenization, ONNX inference, mean pooling, and cosine similarity computation. Key features: - Direct ONNX Runtime with embedded WASM (no transformers.js wrapper) - Custom WordPiece tokenizer (pure JavaScript, 1-2ms per query) - 384-dimensional embeddings with mean pooling - Cosine similarity for semantic matching - SEA-compatible architecture with base64 WASM embedding
- add WordPiece tokenizer for ML model integration Implements pure JavaScript WordPiece tokenization for BERT/MiniLM models: WHAT IT IS: - Subword tokenization used by transformer models - Converts text → token IDs for ONNX Runtime - Zero ML dependencies, pure JavaScript HOW IT WORKS: 1. Basic tokenization (whitespace + punctuation splitting) 2. Greedy longest-match from vocabulary 3. Add special tokens ([CLS], [SEP], [UNK]) 4. Convert tokens to numeric IDs 5. Generate attention masks PERFORMANCE: - ~500KB vocab file (loaded once, cached) - ~1-2ms per query tokenization - Zero runtime ML overhead EXAMPLE: Input: "fixing vulnerabilities" Tokens: ["[CLS]", "fix", "##ing", "vulnerability", "##ies", "[SEP]"] IDs: [101, 8081, 2075, 23829, 2497, 102] FILES: - src/utils/wordpiece-tokenizer.mts - Core tokenizer implementation - src/utils/wordpiece-tokenizer.test.mts - Comprehensive test suite DOCUMENTATION: - Extensive inline comments explaining each step - Real-world examples from socket ask use cases - Links to original WordPiece and BERT papers
- add hybrid semantic matching for socket ask command Implements progressive enhancement for natural language understanding: Fast Path (instant): - Pattern matching with keyword detection - Compromise NLP for verb/noun normalization - Word-overlap matching with synonym expansion (~3KB semantic index) - Handles 80-90% of queries with zero ML overhead Fallback (50-80ms, high accuracy): - ONNX Runtime with MiniLM embeddings (planned) - Deep semantic understanding for ambiguous queries - Only loads when needed for remaining 10-20% edge cases Infrastructure: - scripts/llm/ directory for semantic tooling - scripts/extract-*-wasm.mjs for WASM bundling - Claude skills in ~/.claude/skills/socket-cli/ for IDE integration - Generic wasm-loader.mjs utility Architecture follows yoga-layout pattern for WASM embedding: - Base64 encode WASM at build time - Synchronous instantiation for SEA compatibility - Full control over loading and initialization
- enhance socket ask with compromise NLP library Add compromise for text normalization to handle: - Verb tenses: 'fixing' -> 'fix', 'scanned' -> 'scan' - Plurals: 'vulnerabilities' -> 'vulnerability' - Natural phrasing: 'Can you scan...' -> 'scan' Improves pattern matching accuracy by ~10-15% while maintaining fast response times (<100ms). Falls back gracefully if NLP fails. Size impact: +3MB (acceptable for dev tool)
- implement socket ask command with natural language processing - Add cmd-ask.mts with --execute and --explain flags - Add handle-ask.mts with pattern matching engine - Priority-based matching (fix/patch/optimize > scan/package > issues) - Extracts severity, environment, package names, dry-run mode - Confidence scoring for intent matching - Add output-ask.mts with rich formatted output - Color-coded query interpretation - Command preview with syntax highlighting - Detailed explanations of what commands do - Project context display (dependency counts) - Register command in src/commands.mts - Fix yoga-layout patch to remove restrictive exports Pattern matching maps natural language to Socket CLI commands: - 'fix critical issues' → socket fix --severity=critical - 'apply patches' → socket patch - 'optimize dependencies' → socket optimize - 'is express safe' → socket package score express - 'scan for vulnerabilities' → socket scan create
- enhance patch command functionality Add new patch discover, download, and status subcommands with improved UX
- register rm and cleanup subcommands in patch command Added cmdPatchRm and cmdPatchCleanup to the patch command's subcommand registry. This enables users to run socket patch rm and socket patch cleanup commands. All subcommands are now registered: - apply: Apply patches with backup creation - cleanup: Clean up orphaned backups - get: Download patch files - info: Show patch details - list: List all patches - rm: Remove patch and restore backups
- integrate backup system with patch apply Integrated Phase 1.1 backup system into patch apply command. Before applying any patch, createBackup() is called to store the original file contents. This enables safe rollback via socket patch rm. Changes: - Import createBackup from backup utilities - Add patchUuid parameter to processFilePatch - Create backup before copying patched file - Log backup creation and continue on backup failure - Pass patch UUID from manifest to backup system This completes the backup integration loop: - apply: creates backups - rm: restores backups - cleanup: removes orphaned backups
- add patch cleanup subcommand for backup management Implemented socket patch cleanup to manage orphaned patch backups. Supports three modes: - No args: Clean up orphaned backups (not in manifest) - UUID: Clean up specific patch backups - --all: Clean up all patch backups Uses Phase 1.1 backup system APIs: - listAllPatches() to find all backup UUIDs - cleanupBackups() to remove backup data Includes 7 comprehensive tests covering help, missing directory, cleanup modes, and all output formats.
- add patch rm subcommand with backup restoration Implemented socket patch rm
<PURL>to remove applied patches and restore original files from backups. Uses the Phase 1.1 backup system to restore files and clean up backups. Supports --keep-backups flag to preserve backup files after removal. Integrates with: - restoreAllBackups() to restore original files - cleanupBackups() to remove backup data - removePatch() to update manifest Includes 8 comprehensive tests covering help, missing PURL, patch not found, removal without backups, and all output formats. - add patch get subcommand Implemented socket patch get
<PURL>to download patch files from the .socket/blobs directory to a local directory for inspection. Files are copied with their directory structure preserved. Supports custom output directory via --output flag. Supports JSON and markdown output formats. Ready for tests to be added in next commit. - add patch info subcommand Implemented socket patch info
<PURL>to show detailed information about a specific patch. Displays all vulnerability details (GHSA IDs, CVEs, severity, descriptions), file changes with before/after hashes, and patch metadata (UUID, description, tier, license). Supports JSON and markdown output formats. Includes comprehensive tests covering help, missing PURL, patch not found, and all output formats. - add patch list subcommand Implemented socket patch list to display all patches from the manifest. Shows PURL, UUID, description, exported date, file count, vulnerability count, tier, and license for each patch. Supports JSON and markdown output formats. Includes comprehensive tests covering help, error cases, and all output formats.
- add handle test helper infrastructure Add setupStandardHandleMocks helper for handle function tests: - Automatic function name derivation from module paths - Module-level mock setup for vi.mock hoisting - Clear pattern for testing fetch + output orchestration - Comprehensive JSDoc with usage examples
- use unified runner for all test stages with Ctrl+O support - Use unified-runner for checks, build, and tests (not just tests) - Display "Press Ctrl+O to show/hide output" hint at start - Eliminates spinner artifacts in logs - Provides consistent Ctrl+O toggle experience throughout - Cleaner output with no leaked spinner frames
- improve test script output consistency and masking - Replace createSectionHeader with printHeader for consistent formatting - Mask build output with spinner instead of showing verbose logs - Only show build output on failure - Aligns socket-cli test runner with socket-registry style
- add unified runner with Ctrl+O toggle for test output - Added unified-runner.mjs for consistent interactive output control - Updated test.mjs to use unified runner for TTY sessions - Added test setup file to suppress debug output - Configured vitest to use setup file - Provides consistent Ctrl+O toggle behavior across socket-* repos
- add IPC validation module for inter-process communication - Add runtime validation for IPC messages - Implement type guards for IPC handshakes and stubs - Add helper functions for creating and parsing IPC messages - Ensure type safety for socket-cli inter-process communication
- add bordered input and lazy ink utilities - Add bordered-input.mts for styled terminal input - Add lazy-ink.mts for lazy loading ink components
- add interactive help system for better UX - Replace verbose --help output with interactive category selection - Support --help=category for direct category access - Categories: scan, fix, pm, pkg, org, config, ask, all, quick - Shows 'What can I help you with?' prompt with numbered options - Non-interactive terminals show category list with instructions - Maintains backward compatibility with --help-full for full output Examples: - socket --help # Interactive category selection - socket --help=scan # Show scan commands directly - socket --help=quick # Show quick start guide - socket --help-full # Show original full help
- add project context awareness and rich progress utilities - Add project context detection for package managers and frameworks - Add rich progress indicators for better UX during long operations - Create foundation for Claude CLI-like enhancements - Support for multi-progress bars, spinners, and file progress - Auto-detect npm/yarn/pnpm and provide contextual suggestions
- add trusted publisher verification script - Check if all @socketbin packages exist on npm - Verify provenance attestations if present - Check GitHub workflow configuration - Verify NPM_TOKEN secret (if accessible) - Provide clear status and next steps Run with: node scripts/verify-trusted-publisher.mjs
- add placeholder packages for @socketbin namespace - Create placeholder packages at v0.0.0 for all 6 platforms - Add script to generate placeholder packages - Add script to publish all placeholders at once - Add verification script to check packages on npm registry These placeholders are needed to enable trusted publisher configuration. Real binaries will be published at v1.x after trusted publisher is set up.
- implement @socketbin binary distribution system - Add package generator script for creating @socketbin/* packages - Create dispatcher script that selects correct platform binary - Add GitHub Actions workflow for building and publishing with provenance - Update socket package to use optionalDependencies instead of postinstall - Remove install.js in favor of npm's built-in optional dependency handling This new approach eliminates postinstall failures and simplifies distribution
- add catastrophic delete protection to bootstrap remove() - Add inline remove() function with safety checks similar to del package - Prevent deleting cwd or directories outside SOCKET_HOME - Replace all fs.unlink() calls with safe remove() - Protects against accidental system-wide deletions - Can be overridden with force option if needed
- add affected test runner for faster test execution Implements intelligent test selection based on git changes to speed up local development and precommit hooks. Maps source files to their corresponding test files, running only affected tests when possible. Key features: - Detects changed/staged files using git utilities - Maps commands to co-located test files - Maps utils to test files in src/utils/ and test/unit/utils/ - Core files (cli, constants, types) trigger all tests - Supports --staged, --all, --force, and --coverage flags - Builds project automatically if needed
- add experimental bootstrap loader for stub distribution Simple Node.js loader that checks for ~/.socket/_socket and delegates. Foundation for future bootstrap architecture improvements. Not yet integrated with build system.
- add build dependency checker and stub bundle verification - check-build-deps: Verifies build tools, offers UPX installation - verify-stub-bundle: Ensures bootstrap contains only Node builtins - Both support cross-platform (macOS, Linux, Windows)
- add bootstrap stub update capability to self-update command - Add checkAndUpdateStub() to update bootstrap stub during self-update - Check for stub updates even when CLI is up to date - Use stub path from IPC handshake to locate stub binary - Create backups and handle rollback for stub updates - Update both CLI and stub binaries in single self-update operation
- add centralized Ink and React imports wrapper Create src/utils/ink.mts to centralize Ink, React, and InkTable imports with proper tsgo workarounds. Add src/external/ink-table wrapper for proper ESM/CommonJS interop. This eliminates the need for @ts-ignore comments in every TSX file.
- add comprehensive memoization utilities Added full-featured memoization system for caching function results and optimizing expensive computations. Memoization Features: - memoize() for sync functions with configurable caching - memoizeAsync() for async functions with promise deduplication - memoizeWeak() using WeakMap for garbage-collectable object keys - once() for single-execution functions - memoizeDebounced() combining memoization with debouncing - LRU cache eviction when maxSize exceeded - TTL expiration for time-limited caching - Custom key generators for flexible cache keys - @Memoize decorator for class methods Cache Management: - Configurable max cache size with LRU eviction - TTL-based expiration - Access count tracking - Cache hit/miss debugging (DEBUG=cache) - Failed promise cleanup (errors not cached) - Concurrent call deduplication for async functions Test Coverage: - 20 tests covering all functionality (all passing) - Basic memoization with various argument types - Custom key generators - LRU eviction - TTL expiration - Async function handling - Concurrent call deduplication - Error handling - WeakMap garbage collection - once() single execution Usage Examples: - Simple: const fn = memoize((x) => x * 2) - With options: memoize(fn, { maxSize: 100, ttl: 60000 }) - Async: const fn = memoizeAsync(async (id) => await fetchData(id)) - Once: const init = once(() => loadConfig()) - Weak: const fn = memoizeWeak((obj) => transform(obj)) Technical Details: - Zero overhead when DEBUG!=cache - Proper TypeScript generics - LRU access order tracking - High-resolution timestamps - Promise caching prevents duplicate API calls - WeakMap enables garbage collection
- add comprehensive performance monitoring utilities Added full-featured performance monitoring system for identifying bottlenecks and optimizing CLI execution. Performance Monitoring Features: - perfTimer() for timing operations with metadata - measure() and measureSync() for function execution timing - perfCheckpoint() for tracking progress through complex operations - trackMemory() for heap usage monitoring - Performance metrics collection (operation, duration, timestamp, metadata) - getPerformanceSummary() with count, avg, min, max, total statistics - generatePerformanceReport() for formatted output - Automatic cleanup and metric aggregation Integration: - Integrates with DEBUG=perf environment variable - No-op when perf tracking disabled (zero overhead) - Compatible with existing debug logging system - Works with debugFn for console output Test Coverage: - 21 tests covering all functionality (all passing) - Timer operations with metadata - Async and sync function measurement - Error handling and metadata tracking - Summary statistics calculation - Checkpoint and memory tracking - Report generation Usage Examples: - Simple timing: const stop = perfTimer('op'); stop() - Function measurement: const { result, duration } = await measure('op', fn) - Checkpoints: perfCheckpoint('phase-1', { count: 100 }) - Memory tracking: const mem = trackMemory('before-operation') - Summary: printPerformanceSummary() Technical Details: - Uses performance.now() for high-resolution timing - Rounds durations to 2 decimal places - Groups metrics by operation name - Exports all metrics for external analysis - Type-safe with PerformanceMetrics interface
- add intelligent caching strategies and comprehensive tests Added smart caching strategies and comprehensive test coverage for new features. Intelligent Caching Strategies: - Endpoint-specific TTL based on data volatility - Package info: 15min (stable), Issues: 5min (volatile), Scans: 2min (very volatile) - Org settings: 30min, User info: 1hr (most stable) - getCacheStrategy() for automatic TTL selection - shouldWarmCache() for critical data preloading - calculateAdaptiveTtl() for frequency-based TTL adjustment - Cache warming support for faster initial responses Test Coverage: - 23 tests for cache strategies (all passing) - Strategy selection for different endpoint patterns - TTL recommendations based on data characteristics - Cache warming decisions - Volatility detection - Adaptive TTL calculations - 14 tests for table formatting (all passing) - Bordered table rendering with box-drawing characters - Simple table rendering without borders - Column alignment (left, right, center) - Color function application - Width calculation with ANSI codes - Missing value handling - Dynamic vs fixed column widths Technical Details: - Pattern matching with glob-style wildcards - Debug logging integration for cache operations - Minimum TTL enforcement (30s) for adaptive caching - Maximum 50% reduction for frequently accessed data
- Enhanced error handling with recovery suggestions Add comprehensive error types with actionable recovery information: - AuthError: Authentication failures with login instructions - NetworkError: Connection issues with retry guidance - RateLimitError: API quota exceeded with wait times and upgrade suggestions - FileSystemError: File operations with code-specific recovery (ENOENT, EACCES, ENOSPC) - ConfigError: Configuration issues with setup instructions Improvements: - Each error type includes contextual recovery suggestions - Recovery suggestions displayed in terminal output with visual hierarchy - JSON output includes recovery array for programmatic consumption - Error display enhanced with cyan 'Suggested actions' section - 41 comprehensive tests covering all error types and recovery utilities Benefits: - Users get immediate, actionable guidance when errors occur - Reduces support burden with self-service recovery steps - Better UX with helpful suggestions vs generic error messages - Consistent error handling patterns across the codebase
- Add command registry infrastructure Add complete command registry system with: - Type-safe command definitions with flags, validation, and hooks - CommandRegistry class for registration and execution - Koa-style middleware composition - Flag parsing (string, boolean, number, array types) - Required flag validation and custom validators - Automatic help text generation - Before/after hooks for command lifecycle - Plugin system for extensibility - 17 comprehensive tests (all passing) Benefits: - Declarative command definitions vs imperative code - Type-safe with full TypeScript support - Self-documenting via auto-generated help - Middleware for cross-cutting concerns - Testable and composable Architecture ready for migration but not yet integrated into CLI entry point. Existing meow-based system continues to work unchanged.
- add comprehensive test utilities Add mock-helpers.mts with SDK/API mocking utilities Add environment.mts with test setup and cleanup helpers Add fixtures.mts with standard test data configurations Add constants.mts with common test values Add index.mts for convenient re-exports
- add core utilities for types, messages, result handling, and logging Add BaseFetchOptions type for consistent SDK options Add centralized error message templates in messages.mts Add result validation utilities with requireOk, map, chain functions Add command-scoped logger with context for better debugging
cli— use direct env reads for HOME in 5 commandsci— complete dependency caching for all test jobsci— add dependency caching to GitHub Actionspublish— optimize CLI build and consolidate platform definitionssea— parallelize binary injection for 8x faster buildscli— add Node.js memory allocation flags for large buildsscripts— optimize build processcli— defer registryUrl lookup until neededsmol— use vm.compileFunction() and remove internal path remappingci— implement critical workflow optimizationsci— add Emscripten SDK and pip caching to build-sea workflowci— add Emscripten SDK and pip package caching to WASM workflow- optimize CI and test performance
- remove lazy-loading of bun lockfile parser
ci— add caching to build-deps jobsci— increase max parallel builds to 6 for SEA and smol workflowsci— add pip cache for Python dependencies in AI models buildci— optimize runner allocation and switch to Ninjaci— optimize binary builds with ccache and faster runnerswasm— switch to single-threaded ONNX Runtime varianttest— maximize thread pool based on CPU countbuild,test,ci,docs— apply socket-sdk-js optimizations across all phases
lint— split oversize modules, type the build scripts, restore output-assertions helperlint— clear remaining non-split findings — identity assertions, template method order, changelog formatci— clear fleet gate findings — patch rationales, soak globs, userconfig opt-out, run-s globsbuild— repair createHash import and drop unpublished lib-stable external/semver subpathbuild— restore pipeline modules and exports the dead-code sweep removed while still importedbuild— restore build-pipeline.mts — scripts/build.mts still imports runPipelineClici— refresh external-tools pins to fleet data formatconfig— repo.type is mono, not monorepodeps— bump vulnerable packages to soaked patched versionssea— repoint build-sea/test-sea imports at sea-build-utils dirdeps— pin rolldown to soaked 1.0.3, matching the fleet baselinelint— migrate socket-hook markers to socket-lint prefixscripts— delegate all test scopes to per-package in no-config workspacesdeps— migrate source to lib-stable 6.0.7 APIscripts— make fleet test runner monorepo-safe and drop pnpm execscripts— import logger in sync-checksums so log calls don't ReferenceErrorhooks— repoint commit-msg husky shim to .git-hooks/fleet/hooks— repoint husky shims to .git-hooks/fleet/ after segmentationdebug,git— redact GitHub token in debug log; use debugNs for level namespacesmcp— bind unauthenticated HTTP transport to loopback + cap POST bodyscripts,format— repair migration-orphan imports/paths + format-script scopedeps— bump vitest to 4.1.6 to clear GHSA-5xrq-8626-4rwphooks— declare shell-quote dep so _shared parser resolvestsconfig— point extends at .config/fleet/tsconfig.base.jsonbuild— migrate remaining external-tools.json tools to platforms schemabuild— migrate pnpm external-tools entry to platforms schemalint— revert colocate work in packages/cli/src — fleet rule requires exportrich-progress— restore inadvertently-deleted file + v6 leaf importrich-progress— inline socket-hook marker so logger-guard sees it on the right linebuild— give each downloaded asset its own subdir to avoid .version racemcp/transport-http— drop| undefinedfrom McpHandleRequest's auth fieldlint— convert file-scope oxlint disables + clear other violationspackageManager— bump pnpm@11.0.8 → pnpm@11.1.2- stop oxfmt from reformatting wheelhouse-schema.json
scripts/check-prompt-less-setup— drop never-used writeFileSync + isLinuxdeps— restore -stable catalog aliases for self-named fleet packageslint— clean lint debt in packages/cli/scripts + srctypes— restore explicit-undefined on AuthenticatedRequest.authtypes— resolve 4 tsgo errors in clivitest— drop orphan base config + fix stale isolate commentscripts— restore spawnSync import in bootstrap-firewall-depsdeps— bump hono to 4.12.18, fast-uri to 3.1.2 for CVE patcheslint— dlx test polish — import-type, max-file-lines, sorttypes— resolve noUncheckedIndexedAccess + noUncheckedSideEffectImportslint— generate-report.test — max-file-lines legitimate bypasslint— cmd-manifest-cdxgen — exported helpers + cached for-looplint— telemetry — prefer-function-declaration + cached-for-looplint— mark Set-iteration for-of as intentional in 3 siteshook— mark progress-bar stderr writes as intentionallint— clear remaining socket/* rule violations in cli packagelint— scripts and package-builderlint— cache array.length in build-infra for-loopssync— cascade prefer-cached-for-loop let/const preservation patchlint— sort-source-methods - reorder 20 src files + oxfmt drifttests— restore vi.mock named exports for node:fs / node:os after import refactorlint— autofix sort-source-methods (13 files) + cascade canonical script fixeslint— close out non-blocked socket-cli rulestypes— no-explicit-any — final 29 src files (1-site fixes, brings count to 0)types— no-explicit-any — 11 src files, mostly 2-3 sites eachtypes— no-explicit-any — 7 src files (pull-request, update-manifest, scan-from-github, lockfile-readers, errors, package-alert, shallow-score)types— no-explicit-any — second-pass test files for return / tuple positionstypes— no-explicit-any — top 6 src files (logger, api-wrapper, builder, meow, api, simple-output)types— consistent-type-imports — hoist 30 inline import() annotations across 19 test filestypes— no-explicit-any — replace any with unknown in test files (batch 3/3)types— no-explicit-any — replace any with unknown in test files (batch 2/3)types— no-explicit-any — replace any with unknown in test files (batch 1/3)imports— node-builtin — inline-disable 6 test files using fs as valuetypes— consistent-type-imports — hoist 29 inline import() annotations across 15 test filestypes— consistent-type-imports — hoist 29 inline import() annotations across 15 test filestypes— consistent-type-imports — hoist 16 inline import() annotations across 10 test filestypes— iocraft — add namespace import for ComponentNode type castimports— node-builtin — remove dead fs imports in 5 test filestypes— consistent-type-imports — hoist 12 inline import() annotations across 5 test filesimports— node-builtin — 7 files converted to named importstypes— consistent-type-imports — hoist inline import() in sdk-test-helpers.mtsregex— sort-regex-alternations — 8 rewrites + 1 order-significant disabletypes— consistent-type-imports — hoist inline import() in iocraft.mtstypes— consistent-type-imports — hoist inline import() in spawn-node.mtstypes— consistent-type-imports — hoist inline import() in types.mtsimports— node-builtin — 5 files converted to named importsimports— node-builtin — 6 files converted to named importslint— sort-named-imports — inline-disable intentional domain-grouped barrel importlint— max-file-lines — file-level bypass on 86 oversized fileslint— no-fetch-prefer-http-request — inline-disable 5 dev-script fetches that need raw Responselint— apply 2nd-pass oxlint autofixes — sort-source-methods reorder 3 fileslint— personal-path-placeholders — file-level disable on fixture tests + replace example usernames in src commentslint— prefer-exists-sync — rewrite 2 fileExists helpers + inline-disable legitimate metadata readsoxlint— rewrite overrides patterns as /scripts/ etc.lint— export-top-level-functions — collapse 5 export-block aggregatorslint— apply oxlint autofixes — export-top-level-functions / prefer-exists-sync / prefer-node-builtin-imports / sort-equality-disjunctions / prefer-undefined-over-nullno-status-emoji— cascade rule self-disable + bypass scripts/testslint— re-cascade canonical oxlint plugin rules — undo self-corruption- lint --fix autofix pass + cascade canonical check-paths.mts
tests— align 39 assertions with null→undefined fliptypes,quality— revert Object.create(undefined) regression + finish null→undefined flipcli— registermcpin canonical bucketed-commands setdeps— bump hono via override to ≥4.12.16 (CVE patched)hooks— release-workflow-guard — multi-root dry-run resolutionhook— release-workflow-guard — derive project dir from script pathhooks— tighten npx-scanner regex to skip identifier/key contextsdeps— override ip-address >=10.1.1 (GHSA-v2v4-37r5-5v8g)hooks— anchor hook commands + project paths to $CLAUDE_PROJECT_DIRtest— repair four CI-failing assertions on maindeps— regenerate pnpm-lock.yaml for catalog driftcli— stop socket cdxgen from silently shipping empty-components SBOMs (#1266)cli— error messages in env/ + constants/ + sea-build scripts (#1258)cli— error messages in utils/ misc (flags, fs, git, npm, promise, terminal) (#1260)cli— error messages for utils/update + utils/command + error library migration (#1257)cli— error messages in utils/dlx/ (#1256)cli— error messages in commands/ (14 commands + their tests) (#1255)cli— align test/ error messages with 4-ingredient strategy (#1259)cli— return org slug, not display name, from org resolution (#1232)deps— bump nanotar 0.2.0 → 0.2.1 to patch path traversal (CVE-2025-69874) (#1250)debug— log structured HTTP error details instead of raw response (#1233)test— pass --passWithNoTests to vitest (#1240)scan— surface GitHub rate-limit errors in bulk repo scan (#1235)fix— validate target directory and detect misplaced IDs (#1227)api— include request path in API error messages (#1224)api— distinguish 401 (auth failure) from 403 (permissions) (#1226)scan— respect projectIgnorePaths from socket.yml (#1225)ci— replace close/reopen hack with workflow_dispatch for bot PRs (#1210)build— improve asset download resilience against rate limits (#1201)config— align .npmrc and pnpm-workspace.yaml for pnpm v11 (#1198)hooks— normalize platform keys and strip host prefix from repository (#1194)hooks— use strings for binary file scanning in pre-push (#1196)hooks— update zizmor repo from woodruffw to zizmorcore (#1191)deps— bump vite to 7.3.2 (security) (#1168)ci— harden weekly-update — allowedTools, two-phase update, diff validation (#1159)- move minimum-release-age to pnpm-workspace.yaml (#1158)
build— fix runtime bugs in build scripts (#1148)- upgrade handlebars to 4.7.9, fix pre-push hook (#1134)
- upgrade brace-expansion to 5.0.5 (CVE-2026-33750) (#1132)
ci— rebuild weekly-update.yml with proper YAML and features- harden GitHub Actions workflows (#1129)
ci— update pnpm/action-setup to Node 24 (58e6119)skill— update updating skill to use pnpm run update and check --allci— add timeout-minutes and shell declarations to workflowsci— add explicit shell: bash declarations to provenance workflowtypes— remove unused import and fix context testssecurity— make missing SHA-256 checksums a hard errorci— add complete stub package with JS implementation for iocraftci— create stub packages before pnpm installci— setup pnpm before node to enable cachetypes— resolve TypeScript type errors in iocraft and test helperstui— fix border rendering in iocraft column layoutsdeps— remove stale restore-cursor patchdeps— remove stale React/Ink dependencies after iocraft migrationtest— replace unsafe fs.rm with safeDeletecli— improve cache coherency and notification handlingcli— handle undefined returns from getMajor in optimizesecurity— address critical security vulnerabilitiescli— invalidate token cache on login/logoutcli— correct unreachable error branch in scan-diffiocraft— critical publishing workflow fixespublish— use separate versions for cli and iocraft ecosystemsiocraft— use independent versioning starting at 1.0.0-pre.0cli— transform yoga-sync.mjs to remove top-level await for CJS- use 0.0.0 for placeholder version (matches existing pattern)
- properly disable dependabot (#1119)
publish— rename workflow to provenance.yml for trusted publishingpublish— restore socket package and fix pathsci— read base version from cli-package templatepublish— add missing check-version-consistency script and update docssfw— use separate versions for SEA and npm CLI distributions- address quality scan findings (Round 1)
dry-run— show computed query parameters in read-only commandscli— enhance fix dry-run to show computed detailscli— improve optimize dry-run and remove unused logger importsquality-scan— remove socket-btm cross-project referencescli— replace broken --dry-run with meaningful preview outputtest— inject inlined env vars in test setup for e2e testsci— remove integration tests job (no integration tests exist)ci— simplify CI workflow and remove references to non-existent directoriesci— use pnpm/action-setup to read packageManager from package.jsonquality— add try-catch for JSON.parse in build scriptsquality— add defensive checks and fix Windows ARM64 Python detection- quality scan fixes - NaN validation, logging conventions, docs
sea— use relative paths in sea-config and update SDK- remove cross-repository updates from quality-scan skill
sea— update Trivy to v0.69.2sea— use win32 platform keys in external-tools-platformsvfs— update mount type signature to asyncPromise<string>sea— fix sfw extraction from VFS with node_modules structuresea— add Socket Firewall (sfw) to VFS bundlingscan— correct policy strictness comparison in alert aggregationhooks— check only new commits in pre-push, not all since releasehooks— use portable for loop instead of process substitution in pre-pushcli— address quality scan findings round 10package-builder— correct dependencies for cli-with-sentry templatecli— restore 'as unknown as' pattern in type assertionscli— handle negative time deltas in msAtHome functioncli— add defensive optional chaining in getHighestEntryIndexcli— address remaining round 17 low priority issuescli— address round 17 quality scan findingscli— improve type safety by replacing unsafe type assertionscli— remove globalThis indirection in update notifiercli— improve Coana output parsing to handle empty linescli— add HTTP request timeouts to prevent indefinite hangscli— restore and fix handle-optimize.test.mtscli— resolve TOCTOU race conditions in file cleanupcli— replace Math.random() with fixed delay in preflight downloadscli— address quality scan findings round 9cli— address quality scan findings round 8cli— prevent unbounded Map growth in inflight trackerscli— code style consistency - catch parameter naming and type safetycli— add missing lru-cache dependencycli— address quality scan findings round 4 (part 2) - lock detection and race conditionscli— address quality scan findings round 4 (part 1)cli— address quality scan findings round 3cli— capture timestamp at function entry for accurate TTLci— add required .env.precommit for pre-commit hooksci— improve workflow reliability and security validationcli— add input validation and bounds checkingcli— resolve race conditions and improve locking mechanismscli— resolve memory leaks and resource cleanup issuescli— fix getMaxOldSpaceSizeFlag default calculationhooks— add prerequisite checks to pre-commit hookcli— address quality scan findings round 11cli— address quality scan findings round 10cli— address quality scan findings round 9cli— address quality scan findings round 8cli— address quality scan findings round 7cli— address round 6 quality scan findingscli— address round 5 quality scan findingscli— address quality scan findings (round 4)cli— address quality scan findings (round 3)cli— address quality scan findings (round 2)cli— address quality scan findings across codebasecli— inject external tool versions in integration test runnerscripts— use absolute paths for validation scripts in check.mjstypes— resolve TypeScript errors in spawn usage and unused importstypes— resolve TypeScript errors in quality scan fixesbuild— resolve TOCTOU races and cache invalidationcli— improve type safety in spec parsing and overridesscan— resolve critical bugs in scan output handlersbuild— remove redundant warning emojis from logger.warn callsdeps— always update Socket packages in update script (#1059)deps— add restore-cursor signal-exit v4 compatibility patchdeps— update @socketsecurity/lib to v5.5.3 and add signal-exit v4 compatibility patchesdeps— update Socket packages regardless of taze result- prevent heap overflow in large monorepo scans (#1041)
- remaining fixes from PR 1025 (#1027)
- ensure build directory exists before writing yoga placeholder
- remove unused silence parameter from FetchOrganizationOptions type
- update extract scripts for corrected socket-btm asset names
- implement findAsset locally, remove non-existent import
- exit with code 1 when socket ci finds blocking alerts
security— disable automatic caching in setup-node to prevent cache poisoningsecurity— resolve artipacked and docker security vulnerabilitiessea— use unique cache directories for parallel binject buildssea— add exit code checking for binject spawnbuild— use bracket notation for TypeScript index signaturesbuild— add GitHub API authentication to avoid rate limitsdeps— Remove http2 module dependency from @sigstore/signcli— add per-platform caching for parallel SEA buildsbuild-infra— add GitHub token authentication to API requestsbuild-infra— Add GitHub API headers to httpRequest callsglob— add dot:true to match dotfiles and dot directoriesoptimize— remove Node.js version filter from manifest entriessea— use toUnixPath for Git Bash tar compatibilitysea— use current Node.js process for SEA blob generationsea— update binject command and node-smol URL formatdebug— use correct debug functions with proper namespacingscan— use Octokit for GitHub API calls with proper error handlingci— add Node.js and pnpm setup immediately after checkout in all workflowssea— compute rootPath in getBinjectPath functionbuild— use yoga-sync.mjs from socket-btm and integrate binjectcli— resolve socket-lib external paths at any nesting depthbootstrap— remove non-existent polyfill imports and fix build errorsfix— add ecosystems support to coana CLI callsfix— add --limit as alias for --pr-limitflags— make --exclude and --include visible in socket fix commanddlx— support Coana CLI binary execution via SOCKET_CLI_COANA_LOCAL_PATHdocs— remove hardcoded personal paths and realistic API key exampleshooks— limit pre-push AI attribution check to commits since latest release- upload manifest files relative to target for coana-fix and perform-reachability-analysis
self-update— implement bootstrap binary path via IPC handshakeapi— improve CVE to GHSA conversion caching and error messagingcli— resolve --limit flag not working in local modefix— improve PR creation logic and branch lifecycle managementdlx— pin Coana to exact version without tilde prefixalerts— respect SOCKET_CLI_API_TOKEN environment variabletest— resolve flaky TTL boundary test by mocking Date.now()build— inline environment variables to prevent package.json errorsshadow— use static imports for shadow bins instead of dynamic requirespawn— add which() resolution for command spawnsdeps— fix bin entries and standardize engine requirementsui— change error badge text from red to white on red backgrounddeps— resolve ANSI bundling compatibility issuesbootstrap— use consistent naming for published build flagdev— improve fresh clone developer experiencebuild— fix bundle dependencies validation and add missing depsbuild— add TypeScript dependency and fix socket-lib bundlingbuild— update pnpm and fix CLI build with socket-lib 3.3.2test— fix test infrastructure and ensure build before test:allbuild— fix bundle dependencies validationsetup— verify gh CLI is accessible after installationcli— add missing subcommands to help menu validationhooks— improve AI attribution detection in pre-push hookhooks— use printf for colored output in pre-push hookworkflows— resolve all zizmor security findingssocket— correct package.json metadata and build scriptsocket— add missing version defines to bootstrap build configcli— add src to files array for bin entrycli— rename duplicate dev script to dev:watch for claritytypes— resolve TypeScript errors in package manager commandshooks— improve git hook compatibility and formattingsmol-builder— fix spawn import in compress-binary scriptsmol-builder— fix smokeTestBinary API mismatchsmol-builder— standardize brotli2c naming to socketsecurity_ prefixsmol-builder— convert remaining patches to standard unified diff formatsmol-builder— convert polyfill patches to standard unified diff formatsmol-builder— regenerate polyfill patches with real git hashessmol-builder— replace fs.rm with safeDelete for secure deletionsmol-builder— replace remaining rm calls with fs.rmsmol-builder— replace cp with fs.cp for file copy operationssmol-builder— add readdirSync back to fs importssmol-builder— replace remaining mkdir calls with safeMkdireslint— enable no-undef rule for script filessmol-builder— use fs.method() pattern for all fs.promises callssmol-builder— replace mkdir with safeMkdirsmol-builder— copy bootstrap loader to lib/internal before compilationsmol-builder— correct brotli2c patch line numbers for pristine Node.js v24.10.0sea-builder— remove erroneous closing brace causing syntax errorsmol-builder— copy brotli header to src directorysmol-builder— update hardcoded patch reference to use numbered prefixtest— correct import path for confirm promptbootstrap— use major version only for CLI download specsmol— implement robust cross-platform strip with capability detectionsmol— use platform-specific strip flags for binary optimizationsmol— use shell for execCapture and enable fail-fast for buildsbootstrap— show Socket CLI version instead of Node.js versionbootstrap— skip preflight on --version for instant responsesmol— skip CLI bootstrap for basic Node.js operationsci— make WASM optional in SEA builds with graceful fallbackci— remove ai-cache-valid references from build-sea workflowci— comment out socketbin-cli-ai references in build-sea workflowci— update ONNX Runtime artifact verification to check for .mjs filesonnx— add existence checks to patch verificationonnx— verify wasm_post_build.js patch in cache validationonnx— clean stale cache after GitHub Actions restorationonnxruntime— patch wasm_post_build.js in both source and build directoriesbootstrap— remove unnecessary empty log after spinner completestest— reduce thread count on macOS CI to prevent SIGABRTtypes— resolve exactOptionalPropertyTypes issue in UpdateStoreupdate— only show content-type warning in debug mode on parse failuretypes— correct parameter types for SDK method callstypes— add explicit type parameters to handleApiCall callstypes— update handleApiCall signature for SDK v3 compatibilitytypes— revert to use SDK v3 method names in type referencestypes— update SDK operation names to match API typesdeps— update all packages to use catalog for @socketsecurity/liblint— fix all lint errors and update dependenciesbuild— externalize Socket dependencies and add bundle validation test- update for @socketsecurity/lib 3.0.5 compatibility
build— use default export workaround for CommonJS imports with --import flagtest— resolve TypeScript errors and test failures in NLP modulessmol— use Module.prototype.require.bind for virtual modulesmol— use Module.createRequire for proper module contextonnx— patch wasm_post_build.js to handle modern Emscriptenbootstrap— correct stream/promises module path for smol buildsci— remove expression from build-models job namemodels— correct --all flag logic to build both modelsci— build all AI models in workflowmodels— check for all expected ONNX files during conversionmodels— fix method variable scope in quantization fallbackci— remove invalid job-level matrix conditions from workflowsonnxruntime— remove EXPORT_ES6=0 patch for threading compatibilityonnxruntime— enable threading and SIMD for v1.21.1 compatibilityci— mark ONNX Runtime WASM build as non-blockingmodels— update INT4 quantization API for onnxruntime 1.20+ci— install optimum[onnxruntime] for ONNX model exportonnx— remove ES module type from onnxruntime package.jsonsocket— remove bootstrap-smol.js from npm package buildpatch— remove unused imports after duplicate logging removalpatch— remove duplicate output logging to fix markdown test flakinesspath— handle UNC paths correctly on Windowspath— add Windows validation for Unix-style paths in findNpmDirPathSyncwasm— update INT4 quantization to use matmul_nbits_quantizer APIci— pin onnxruntime>=1.20.0 to ensure INT4 quantization supportci— upgrade onnxruntime and add INT4 quantization toolsci— uncomment ONNX Runtime build steps to fix bash syntax errorbootstrap— eliminate spurious error message on successful CLI execution- improve bootstrap error handling
completion— resolve CLI package root correctly for tab completion scriptscan— flatten SDK options and make repo parameter conditional- restore v1.x environment variable fallbacks and EEXIST handling
smol— enable code cache for brotli decompression support- run build before verify in socket package
- inject MIN_NODE_VERSION in bootstrap esbuild configs
- use logger.fail for error messages in verify script
- read CLI version from socket package.json during build
cli-with-sentry— add missing esbuild config for shadow-npm-injectcli-with-sentry— add missing shadow-npm-inject build stepbuild— skip onnxruntime build (temporarily disabled)gitignore— allow docs/build directory without requiring -f flag- resolve TypeScript errors after nodeDebugFlags removal
- remove nodeDebugFlags references
build— align platform/arch flags in build-all-binariesbuild— disable minifySyntax across all esbuild configssocket— disable minifySyntax to prevent async function boundary corruptionci— align smol cache keys with build-smol.yml in publish-socketbin.ymlci— use SEA binary cache from build-sea.yml in publish-socketbin.ymlsbom-generator— resolve exactOptionalPropertyTypes type errorstest— use proper function syntax for Vitest constructor mockslint— resolve lint errors and remove dead getInternals codenode-sea-builder— add missing crypto importbootstrap— improve error handling for CLI download failurescli— update getBinCliPath to use dist/index.js instead of bin/cli.jsenvironment— remove unused createRequire importenvironment— lazy-load bun lockfile parserinstall— download from npm registry instead of GitHub releasesprepare— remove dotenvx wrapper from husky prepare scriptworkflow— specify correct build target for cli-with-sentryworkflow— update JS-only fallback validationcli-with-sentry— use dist/index.js and validate cli.js.bzcli-with-sentry— use socket-with-sentry bin namecli-with-sentry— move @sentry/node to dependenciesci— validate yoga WASM cache instead of building on missci— publish from package directories and build yoga WASM on cache missci— replace obsolete external cache with yoga-layout WASM cachescripts— update dist validation to check for index.js and cli.js.bzscripts— update pre-publish-validate to accept package pathscripts— remove duplicate colors declaration in pre-publish-validateci— use 'pnpm run build' instead of non-existent 'build:dist'packages— run pnpm pkg fix to normalize package.json fieldssocketbin— add repository field to all package.json filesci— add --tag latest to all npm publish commands for prerelease versionsci— use semver to extract X.Y.Z from package version before appending timestampscripts— skip socketbin-cli-ai version check (not published by workflow)scripts— skip root package.json check for socketbin versionsci— install dependencies before version consistency checkci— use bash shell for verify binary step on Windowsci— skip smol build when method=sea and use bash shell for Windows compatibilityci— use 2-core runners in publish-socketbin for better availabilityci— comment out ONNX runtime in build-sea workflowci— correct ONNX package paths in build-sea workflowci— correct SEA builder package name in publish-socketbinci— add CLI build step before SEA binary build in publish-socketbinscripts— prepublish-socketbin should create bin/socket not bin/clici— align publish-socketbin binary paths with build-sea namingci— upgrade actions/cache to v4.3.0 in publish-socketbin workflowscripts— improve type check error output in check scriptcli— add missing INLINED_SOCKET_CLI_PYCLI_VERSION to ENVonnxruntime— correct EXPORT_ES6=0 to output .js files instead of .mjsonnxruntime— add EXPORT_ES6=0 patch and require shim for WASM buildtest— fix scan create tests to use valid directory targetsonnx— disable WASM threading and patch cmake to fix MLFloat16 build errorstest— fix self-update tests by mocking canSelfUpdate and cleaning up leftover directoriesbuild— add missing INLINED_SOCKET_CLI_CDXGEN_VERSION to esbuild configonnxruntime— enable WASM threading to fix MLFloat16 build errorsbootstrap— remove logger usage from smol bootstrap for early initializationtests— fix GitLab provider mock constructortests— fix npm-config mock constructor to work with 'new' operatorscan-reach— handle empty string and undefined outputPath properlycli— inline build-time constants with post-bundle replacement pluginbuild-infra— escape regex patterns for string literal context in Unicode transformonnxruntime— pass WASM_ASYNC_COMPILATION via CMake definesci— use package version for WASM workflow cache keysci— use package version for ONNX Runtime cache keyonnxruntime— update Eigen hash patch for v1.21.1 deps.txt formatonnxruntime— re-clone if Eigen patch not appliedonnxruntime— clean CMake cache when applying Eigen hash patchonnxruntime— apply Eigen hash patch unconditionally- strip placeholder suffix from socketbin versions
publish— read base version from current package being generatedonnxruntime— patch Eigen hash to match GitLab archive formatonnxruntime— disable TLS verification for CMake downloadsonnxruntime— update to v1.21.1 to fix Eigen hash mismatch- remove yoga-layout patch reference from root package.json
cli— handle missing yoga-layout WASM files gracefullybootstrap— avoid logger initialization before stdout is readycli— correct ESLint config paths to monorepo rootbuild— read socketbin spec from actual package.jsoncompress— align cache key generation with socket-libscan— resolve TypeScript errors from merged PRslint— exclude test fixtures from Biome lintinggit— correct import path for paths modulebootstrap— load Intl polyfill before logger to prevent smol build failuretest— delete obsolete bootstrap test and fix provider factory assertionstest— add missing paths mock for provider factory teststest— fix constructor mocks and add missing canSelfUpdate exporttest— replace runCommandQuiet with spawn and fix mock constructorstypes— resolve TypeScript errors in GitLab providercli-with-sentry— write esbuild output and add gitignoresmol— fix MODULE_NOT_FOUND error for socketsecurity bootstrapci— disable pip cache in build-wasm to prevent cache failuresci— correct artifact paths in build-sea workflowci— correct artifact paths in build-smol workflowcli— suppress esbuild warnings in CLI buildci— correct socket package verification in build-sea workflowci— remove CLI build from build-deps job in SEA workflowci— add detailed cache diagnostics to build-sea workflowai— update onnxruntime to 1.21.0+ for INT4 quantization supportci— add WASM asset verification before CLI build in SEA workflowci— include bootstrap deps in SEA binary cache keyci— include bootstrap deps in smol binary cache keysmol— add diagnostic logging for bootstrap file locationci— correct artifact download path and add relocation logicci— add verification step for downloaded build artifactssmol— fail build if bootstrap cannot be copiedlint— remove unused variables and parametersscripts— replace undefined runCommandQuiet with spawnsocket-fix— add missing import and fix optional prNumber typesocket-fix— add remote branch cleanup on PR creation failuresmol— optimize build flow and fix macOS ARM64 signingci— split dependency builds from matrix parallelizationsea— use versionSemver from node-version.json to avoid double 'v' prefixsea— decompress cli.js.bz instead of using build/ intermediatesea— auto-build CLI package when missingci— build bootstrap package before socket and smol/sea builderssocket— reference bootstrap files from packages/bootstrape2e— check JS binary existence before running testse2e— error and exit if binary doesn't exist when explicitly requestede2e— disable Node.js binary forwarding in .env.testcli— remove unnecessary force: true from safeDeleteSync callsbootstrap— export .config/node-version.mjs for workspace importscli— auto-enable RUN_E2E_TESTS when running e2e.mjssocket— handle prefix-only modules in smol transformsocket— correct internal module paths in smol transformci— skip cache restore when force rebuild is requestednode-smol-builder— use socket package bootstrap not local stubnode-smol-builder— add placeholder bootstrap for socketsecurity patchsea-builder— add shell execution for postject on Windowssea-builder— use direct postject path instead of pnpm execsea-builder— add postject as catalog devDependencyci— enable cross-OS cache sharing for Windows buildsci— pass --force flag to WASM build scripts when force rebuild requestedci— move Windows WASM cache check before build attemptci— require WASM cache for Windows SEA buildsci— add wasm-opt to PATH for Windows Emscripten buildssea— strip leading '--' from pnpm arguments for correct parsingsea— enable cross-platform SEA builds using prebuilt Node binariesci— limit SEA builds to native architectures onlyci— correct SEA binary build for cross-platform compilationbuild— resolve SEA build failures across platformspackages— correct spawn result access in package build scriptsbuild— correct spawn result access in build orchestration scriptswasm— correct spawn result property access in WASM build scriptsscripts— resolve duplicate spawn import and incorrect result accessci— remove pip upgrade to improve Python dependency caching- move .node-source to packages/node-smol-builder/build/
onnx— output to dist/ directory instead of build/wasm/ci— save ONNX build cache even on failureonnx— fix second readCheckpoint usage in export stageonnx— use correct checkpoint function namebuild— enable WASM features in wasm-opt optimizationonnx— locate WASM files in MinSizeRel subdirectorysmol— use compressed binary in Final distribution directorybuild— use fs.statfs for reliable cross-platform disk space checkci— use requirements.txt for proper pip cachingonnx— upgrade to v1.23.2 to resolve Eigen hash mismatchwasm— correct checkDiskSpace parameter units (GB not bytes)onnx— use build.sh script instead of direct CMakewasm— use explicit EMSDK paths for wasm-opt and wasm-striponnx-runtime— remove existing source dir before clone and add debug loggingwasm— use shell:true for wasm-opt/wasm-strip to inherit emsdk PATHsocketbin-cli-ai— auto-clean stale checkpoints when artifacts missingonnx-runtime— auto-clean stale checkpoints and use existsSyncyoga-layout— auto-clean stale checkpoints when artifacts missingyoga-layout— throw errors instead of warnings on missing artifactsci— add debugging output for WASM build artifact verificationbuild-infra— replace exec wrappers with direct spawn callsai— add progress indicator for brotli compressionbuild-infra— add exec wrapper to builder classesci— fail builds when WASM artifacts are missingai— define originalSize/quantSize before useci— add cache artifact verification to WASM buildsonnx— use proper spawn command/args pattern- replace build-exec with spawn in remaining builder packages
onnx— replace build-exec with spawnci— replace shasum with sha256sum for Windows compatibilityci— use standard ubuntu-latest runners for WASM buildsnode-smol— use console.log instead of logger.log in binary smoke testcli-ai— make INT4 quantization optional with graceful fallbackci— correct INT4 quantization import and remove invalid autocrlfci— remove push triggers from build-wasm to avoid runner contentioncli-ai— correct import path for matmul_4bits_quantizerci— require onnxruntime>=1.20.0 for INT4 quantizationci— use optimum[onnx] instead of optimum[exporters]build-infra— use result.code instead of result.statusbuild-infra— import printSubstep for debug loggingbuild-infra— use shell for Python detection on all platformsbuild-infra— try multiple Python command names in version checkbuild-infra— handle undefined status in Python checkbuild-infra— fix spawn calls to use proper command+args patternbuild-infra— restore shell: WIN32 option in Python checkbuild-infra— use direct python3 execution without shellbuild-infra— add detailed error logging to Python checkci— add Python verification step for debuggingci— setup Python for all platforms in smol buildci— add Python 3.11 setup for WASM builds in SEA jobbuild-infra— remove duplicate imports in tool-installernode-smol-builder— replace build-exec with spawn wrappersci— add WASM asset restoration to SEA build jobci— correct package names and cache key generationci— ensure dist directories exist before verificationci— include node-smol-builder patches and additions in cache keysci— update patches directory path from build/patches to patchesci— update actions/cache to v4.3.0ci— add workflow_call trigger to build-wasm workflowci— add WASM asset preparation before CI testscli— remove unused imports in optional-models.mtse2e— prompt for sea and smol binaries separatelytest— update tests for read-only ENV properties from @socketsecurity/libtest— skip Unix permission checks on Windowsenv— convert CI to boolean and fix type comparisone2e— correct property names and assertions in critical commands testtests— correct import paths in E2E dlx testtest— correct e2e test exclusion patternpaths— replace path.sep with normalizePath across codebase- use forward-slash patterns for normalized path matching
- normalize paths consistently across platforms
shadow/npm— wrap path.join calls with normalizePathtests— resolve cross-platform npm and path issuescli— resolve TypeScript error in shadowNpmBase cwd handlingcli— pass converted cwd to spawn in shadowNpmBase- improve developer onboarding and fix broken commands
cli— use platform-specific PATH separator in npm tests- remove accidental gitlinks for yoga source directories
cli— make path tests cross-platform compatiblebuild— use fileURLToPath for cross-platform path comparison in esbuildci— prevent diagnostic checks from stopping script executiongitignore— restore dist/ ignore and update build artifact documentationtest— use tmpdir for patch discover test to avoid spawn failuresci— remove del-cli from test-setup-scriptci— remove redundant pnpm install from test-setup-scriptci— replace rm -rf with cross-platform del-cli commandcli— normalize paths for Windows compatibility in completion and tildifycli— update NODE_VERSION to getNodeVersion()cli— skip update checks in test environmentstests— update test imports and fix NpmConfig mockutils— update remaining ecosystem.mjs imports to types.mjscli— update ONNX runtime extractionbuild-infra— improve Emscripten and build executionscripts— add missing colors import in verify-node-builddeps— use socket-lib 1.3.5 with Windows Proxy fixtests— pass undefined env to avoid multiple process.env spreadstests— revert to working spawn pattern from commit 39ee9465tests— use Proxy in test mode to preserve Windows env behaviortests— use exact spawn env pattern from working commit 39ee9465tests— omit env option when no custom env vars providedtests— avoid spreading process.env in spawn callstests— preserve process.env proxy for Windowsci— resolve dependency caching issue causing test failurescli— resolve TypeScript strict mode errorsci— use consistent pnpm --filter pattern in test setupci— use pnpm --filter to run scripts in monorepo contextci— remove redundant cd commands in workflow scriptsdeps— correct @socketsecurity/lib references in workspace packagesscan— add optional chaining for spinner safetypatch— wrap logger output in outputKind checks for JSON/markdownpatch— use optional chaining for spinner to handle null in teststests— update CI handle test imports and debug APItests— update debug imports and skip path-resolve testtests— add missing stdout/stderr destructuring in optimize testscli— disable interactive help menu in test environmentstests— replace await import with vi.importMock in fetch-threat-feed teststests— replace helper functions with direct mocks in fetch-list-repos and fetch-list-all-repostests— replace await import with vi.importMock in remaining repository teststests— use vi.importMock() consistently in fetch-update-repo teststests— rewrite fetch-delete-repo tests to match actual implementationtests— use vi.importMock() consistently in fetch-create-repo testsdlx— skip cache entries with invalid metadata in listDlxCachetests— correct UNKNOWN_ERROR import in errors.test.mtstests— add missing await to async operations in optimize testsci— clear Vitest cache before running teststest— correct mock setup for scan teststest— correct mock setup for repository output teststest— correct mock setup for output-security-policy teststest— correct mock setup for output-quota teststest— correct mock setup for output-license-policy teststest— correct mock setup for output-dependencies teststests— correct import paths and logger references in organization teststests— remove invalid await from destructuring in scan testsconfig— handle Buffer return from safeReadFileSync in findSocketYmlSynctests— update API requirements output test expectationstests— resolve shadow/links PATH and Windows test issuestests— correct socket/alerts mock pathstests— correct pnpm scanning test mockstests— fix environment variable mocking in API teststests— update API error message expectationstests— update CLI behavior expectations for interactive menutests— correct org-slug test mocks and expectationstests— update socket.json test expectationstest— resolve mock configuration issues in validation and helper teststests— update SDK API mock expectations for v3.0.6cli— add ask, console, and patch commands to validation listtests— add missing color functions to yoctocolors-cjs mocktests— correct module import paths in shadow links and performance teststests— correct module file name importstests— correct remaining import paths in test filestests— remove getProcessEnv import that doesn't existtests— correct module mock paths in test helperstests— correct additional import paths in utils subdirectoriestests— correct import paths and remove orphaned test fileswindows— add LOCALAPPDATA fallback for app data pathtest— resolve binCliPath undefined errors and CI shimmer testtest— correct import paths in 76 command test filestest— correct import path in constants.test.mtstest— resolve SDK dynamic require error in vitest configbuild— use getLocalPackageAliases instead of hardcoded pathstest— enable test isolation to prevent worker thread termination errorstest— correct output-threat-feed mock path for serializeResultJsontest— correct arborist-helpers mock path for idToNpmPurltest— correct handle-create-new-scan mocks and expectationstests— properly mock paths and dependencies in postinstall-wrapper teststests— properly mock @socketsecurity/lib/debug in debug tests- resolve socket-lib bundled external dependencies in esbuild
- add missing TypeScript base config at root
- remove @socketsecurity/lib link override for CI build compatibility
- update @socketbin/cli packages to available version 0.0.0
- replace fragile regex parsing with file-based JSON extraction in coana discovery
- resolve pre-existing unit test failures
ci— remove coverage-script and coverage-report-scriptci— update workflow SHAs to d8ff3b05- update build scripts to use pnpm filter for monorepo
- link to local @socketsecurity/sdk for development Replace @socketsecurity/sdk version dependency with link to sibling socket-sdk-js directory. Remove SDK patch as types are now fixed at source. This enables development on SDK and CLI simultaneously and ensures we're testing against the latest SDK changes.
- patch @socketsecurity/sdk@2.0.1 to correct type definition paths The SDK package.json incorrectly references index.d.mts and testing.d.mts but the actual files are index.d.ts and testing.d.ts. This patch corrects the types field to point to the correct .d.ts files. Note: This fixes the "could not find declaration file" errors, but there are still type export issues with SDK v2.0.1 that need to be addressed. Socket CLI uses SocketSdkSuccessResult and other types that are not being properly exported from the SDK index despite being defined in types.d.ts.
- suppress lint warning for intentional control character regex Add biome-ignore comment to asciiUnsafeRegexp which intentionally matches control characters for test output cleanup. This is a false positive from the noControlCharactersInRegex rule.
- suppress lint warning for intentional control character regex Add biome-ignore comment to asciiUnsafeRegexp which intentionally matches control characters for test output cleanup. This is a false positive from the noControlCharactersInRegex rule.
- resolve merge conflict in provenance.yml workflow Remove merge conflict markers and use correct publish command that changes to dist directory before publishing @socketsecurity/cli-with-sentry. This ensures the package is published from the correct location.
- handle directory targets according to specification When a directory path is provided, it now recursively scans that directory for all files by appending /*/ to the path pattern. This ensures directory targets work as expected in scanning operations. Also fixes a type annotation issue in getWorkspaceGlobs. Cherry-picked from PR #794 (commit 5f78dfdf) Original author: Martin Torp martin@socket.dev Co-Authored-By: Martin Torp martin@socket.dev
- disable Biome assist to prevent import organization conflicts
- update Biome and ESLint configs for bracket notation support Update linting configuration to support TypeScript bracket notation for index signature properties: - Disable Biome rules: useLiteralKeys, noParameterAssign, noNonNullAssertion, noExplicitAny, noAsyncPromiseExecutor, noAssignInExpressions, useIterableCallbackReturn, noBannedTypes - Disable ESLint rules: no-unexpected-multiline, sort-imports - Apply Biome formatting across codebase This aligns with socket-sdk-js and enables TypeScript TS4111 compliance.
- inject build metadata in esbuild config After migrating from Rollup to esbuild, build metadata values (INLINED_SOCKET_CLI_VERSION, etc.) were no longer being injected, causing the CLI version to display as "vundefined" in the header. Changes: - Added build-time injection of all metadata values via esbuild's define option (version, version hash, dependency versions, build flags) - Implemented proper version hash computation matching Rollup's logic: "${version}:${gitHash}:${randomUUID}${devSuffix}" - Fixed dependency version lookups to use devDependencies (coana, cdxgen, synp) - Renamed esbuild-inject-import-meta.js to .mjs for proper module resolution - Added default export to scripts/constants.mjs for compatibility - Fixed import order in esbuild.cli.config.mjs - Added biome-ignore comments for ANSI escape code patterns in demo The CLI header now correctly shows the version (e.g., "v1.1.25") and all build constants are properly inlined during bundling.
- improve ask command intent parsing and model loading Cache semantic model loading failures to avoid repeated error messages. Previously tried to load the model 6 times per query, now fails once and caches. Improve package name extraction to reject common command words like 'vulnerabilities', 'security', 'issues'. Only extracts valid package names like 'express', '@scope/package', etc. Fix esbuild import.meta.url injection by using ESM export syntax instead of CommonJS module.exports format.
- link to local socket-registry for development Update package.json to use local socket-registry for development to access latest exports and constants not yet published to npm. Add scripts/constants.mjs barrel file to re-export all constants modules. Fix lint issues: - Add eslint-disable for intentional process.exit() in SIGINT handler - Add eslint-disable for intentional await in loop for sequential URL checking
- patch https-proxy-agent to prevent Rollup template literal corruption Replace \r\n literals with hex codes (\x0d\x0a) to prevent Rollup from corrupting template literals during bundling process.
- skip processing of large base64-encoded WASM/model files Adds custom Rollup plugin to load external/ files raw without parsing. This fixes build hangs caused by Babel/CommonJS trying to parse 40MB+ base64-encoded strings in onnx-sync.mjs and minilm-sync.mjs. Changes: - Add skip-external-assets plugin to load() files raw - Exclude external/from babel processing - Exclude external/ from commonjs processing
- suppress TypeScript errors for local registry imports Add ambient module declarations for @socketsecurity/registry subpaths. This suppresses TS2307 errors during development when using local builds. The Node.js loader resolves these imports correctly at runtime, and build tools use getLocalPackageAliases() for resolution. Update .gitignore to allow src/types/*/.d.ts (ambient declarations).
- restore ink patch with proper git hashes Regenerate ink@6.3.1.patch using pnpm patch workflow to fix integrity check failures.
- ensure fix script forwards --all, --changed, and --staged flags to lint Updates scripts/fix.mjs to properly forward file filtering flags to the underlying lint command. This ensures consistent behavior across socket-cli, socket-packageurl, and socket-sdk-js repositories. - Add --all, --changed, and --staged options to parseArgs - Build lint command arguments conditionally based on flags - Forward flags to pnpm run lint --fix command - Update script documentation with new options
- resolve all ESLint errors and warnings - Fix undefined NODE_DIR by defining it properly in build-yao-pkg-node.mjs - Add eslint-disable comments for intentional unused variables in catch blocks - Add eslint-disable comments for intentional process.exit() calls in SEA wrapper - Add eslint-disable comments for intentional await-in-loop in retry/batch operations - Auto-fix all import ordering warnings across codebase - Ensure proper import grouping: builtin -> external -> internal -> local
- handle deleted files in lint and test scripts - Add existsSync checks to filter out deleted files before linting - Add existsSync checks in affected-test-mapper to skip deleted test files - Prevents 'No files matching pattern' errors when files are deleted This fixes an issue where git reports deleted files in changed/staged lists, but the files no longer exist on disk, causing lint and test runners to fail.
- improve Ctrl+O output display behavior When Ctrl+O is pressed to show output: - Remove "--- Showing output ---" header for cleaner display - Don't clear the buffer after dumping it - Keep output streaming live to stdout while visible - Allow toggling back to spinner mode This provides a smoother interactive experience where pressing Ctrl+O clears the spinner and shows all output, continuing to stream live until toggled back.
- prevent ENAMETOOLONG in path-resolve tests from circular symlinks The test was using mock-fs.load() to load the entire node_modules tree, which followed circular symlinks between @socketregistry/packageurl-js and @socketsecurity/registry infinitely, causing ENAMETOOLONG errors. Additionally, the registry's dist/external/streaming-iterables.js was not accessible in the mock filesystem because Node's require follows the symlink to the actual socket-registry/registry location. Solution: - Don't load the entire node_modules tree (avoids ENAMETOOLONG) - Load only the registry dist from its actual location since require follows symlinks to socket-registry/registry All 21 path-resolve tests now pass.
- correct SDK API calls and TypeScript types - Fix createOrgFullScan call: use options object with pathsRelativeTo and queryParams - Fix streamOrgFullScan call: use options object with output property - Fix purl-to-ghsa: only include affects when truthy to satisfy exactOptionalPropertyTypes - Fix purl types: replace non-existent PurlQualifiers with Record<string, string>
- correct yoctocolors mock in failMsgWithBadge test Move vi.mock() before imports and use plain functions instead of vi.fn() to properly mock the color functions. Remove spy assertion tests that are no longer applicable with plain function mocks.
- add worker termination error handler to test runner Add unhandledRejection handler to filter out non-fatal vitest worker thread cleanup errors. Prevents false negative test failures. Matches socket-sdk-js implementation for consistent behavior.
- use correct TypeScript check script name Change check:types to check:tsc to match the actual script name in package.json.
- use test.mjs script and suppress worker termination warnings - Update package.json test script to use test.mjs for --all flag support - Add --unhandled-rejections=warn to NODE_OPTIONS to suppress non-fatal unhandled rejection warnings from vitest worker thread cleanup This aligns socket-cli with the test infrastructure used in other socket-* repos and prevents false test failures from worker cleanup.
- handle vitest worker termination errors gracefully Update test runner to capture output and detect worker termination errors. Override exit code to 0 when only worker termination errors occur without actual test failures. This prevents false negatives from known non-fatal vitest cleanup issues.
- suppress TypeScript spread type errors with ts-expect-error Add @ts-expect-error comments to suppress TS2698 errors on getOwn spread operations. While spreading undefined technically works at runtime in modern JavaScript, TypeScript's strict mode rejects it. Since the linter strips out nullish coalescing operators, we use ts-expect-error instead. Files updated: - src/commands/optimize/agent-installer.mts - src/shadow/npm/arborist-helpers.mts - src/shadow/npm/install.mts - src/utils/dlx.mts - src/utils/meow-with-subcommands.mts - src/utils/socket-package-alert.mts
- replace log.progress with log.step in build script - Use log.step() instead of log.progress() to avoid spinner interference - Remove manual line clearing code (no longer needed) - Replace log.failed() with log.error() for consistency - Prevents output interference with dividers and status updates
- resolve TypeScript TS2698 spread type errors with exactOptionalPropertyTypes Add nullish coalescing to getOwn() calls to ensure spread operations always receive objects when exactOptionalPropertyTypes is enabled.
- continue resolving TypeScript errors - Fixed EditablePackageJson import to use ReturnType pattern - Fixed Buffer/NonSharedBuffer .trim() issues in update-store.mts - Fixed ChildProcessType exit event parameter types - Fixed debug namespace calls (isDebugNs, debugFnNs) in error-display.mts Reduced errors from 255 to 251
- resolve TypeScript API migration errors - Convert 2-argument debug calls to namespace variants (debugFnNs) - Replace logger.debug with logger.log (API removed in registry) - Update pluralize calls to use { count } option object - Add missing LATEST and PACKAGE_LOCK_JSON exports - Import namespace debug functions in debug utilities Reduced TypeScript errors from 432 to 255
- update @socketbin workflow for trusted publisher - Remove automatic release trigger (manual dispatch only) - Remove all NODE_AUTH_TOKEN/NPM_TOKEN references - Use OIDC authentication via id-token permission instead - Simplify version determination (no release event handling) Trusted publisher uses GitHub OIDC tokens, no npm token needed.
- add file extension filtering to affected test mapper - Skip non-code files (images, docs, etc.) in test mapping - Prevents running all tests for non-code file changes - Improves test performance
- resolve ESLint and TypeScript linting issues Fix inline comment positioning (line-comment-position): - Move inline comments to separate lines above code - Affected: cache-strategies.mts and all test files Fix TypeScript index signature access: - Change dot notation to bracket notation for metadata properties - Affected: performance.test.mts Add ESLint disable comments: - Disable no-control-regex for ANSI color code tests - Affected: output-formatting-tables.test.mts All files now pass
pnpm run checksuccessfully. - use Object.create(null) for ResultErrorOptions Replace proto: null in typed object literal with Object.create(null) Follows CLAUDE.md pattern for empty null-prototype objects
ci— update socket-registry SHA to 5b2880d7ci— update socket-registry SHA to 662bbcabci— update socket-registry SHA to b94a1086ci— update socket-registry SHA to dba06046ci— update socket-registry SHA to 0782233cci— correct socket-registry SHA to full hashci— update socket-registry SHA to 43a668e1ci— update socket-registry SHA to d1bbbbadci— update socket-registry SHA to dc181fb5ci— update socket-registry SHA to 08fba31aci— update socket-registry workflows to latest SHA (c61feb5e)ci— pin socket-registry workflows to SHA instead of @main- improve organization capabilities detection for plan variants
- enterprise plan filter (#785) Signed-off-by: Ahmad Nassri email@ahmadnassri.com Co-authored-by: John-David Dalton jdalton@users.noreply.github.com
- handle pnpm frozen-lockfile in CI for optimize command In CI environments, pnpm automatically runs with --frozen-lockfile which prevents lockfile updates. When the optimize command tries to add overrides and update the lockfile, it fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Added explicit --no-frozen-lockfile flag when running pnpm install in CI mode to allow the lockfile to be updated with Socket.dev overrides.
- Add fallback for npm exec path detection When constants.npmExecPath from the published registry doesn't exist or isn't executable, fall back to using whichBin to find npm. This fixes CI failures where the published version's npm-exec-path module might not correctly detect npm in certain environments.
- Add defensive check for whichBinSync return value The published version of @socketsecurity/registry may return a string when only one result is found even with all: true. This defensive check handles both cases to ensure compatibility with the current published version and future versions that properly return an array.
check— add external-tools-release-tags-resolve gatehooks— add claude-md-size-guard and no-revert-guardcli— add defineHandoffCommand factory for ecosystem hand-off wrappersoptimize— write pnpm 11+ overrides to pnpm-workspace.yamlmcp— port socket-mcp standalone intosocket mcpsubcommandscan— add --exclude-paths flag for full Tier 1 exclusion (port of #1298) (#1306)scan— brotli-compress .socket.facts.json on upload (port of #1291) (#1305)- add xport lock-step manifest tooling (#1284)
- bootstrap @socketsecurity/lib + @socketregistry/packageurl-js + @sinclair/typebox via firewall-checked registry fetch (#1282)
claude— add public-surface-reminder + token-hygiene hooks (#1272)build— port scripts/build.mts to shared build-pipeline orchestrator (#1265)cli— machine-output mode — stream discipline, flag propagation, scrubber (#1234)organization— show quota usage, max, and refresh time (#1236)cli— rename --default-branch (scan create) to --make-default-branch; harden default-branch flags (#1230)- backport v1.x features and DRY out HTTP layer
ci— add updating skill and weekly-update workflowsea— bundle Python packages at build time for offline operationbuild— pre-install socketsecurity into bundled Python for SEAvfs— add opengrep, trivy, trufflehog, python to SEA VFS extractionsecurity— add SHA-256 verification for PyPI package downloadssecurity— add SHA-256 checksum verification for PyCLI (socketsecurity)build— add npm package integrity verificationbuild— inline all external tool checksums at build timedlx— add SHA256 checksum verification for Python and socket-patch downloadstui— add advanced iocraft components and styling featurestui— add comprehensive terminal UI property supportiocraft— add binary download mechanism from socket-btmiocraft— add author field to platform packagespublish— use 'pre' dist-tag for all pre-release packagesiocraft— use 'pre' dist-tag for pre-release versionsiocraft— add MIT LICENSE files to socketaddon packagesiocraft— add @socketaddon/iocraft v3.0.0-pre.0 package infrastructurepublish— make dry-run first option and default to truesocket— add bootstrap loader for @socketbin/* binariesscan— add --workspace flag to scan create command- BREAKING:
patch— migrate socket-patch to v2.0.0 Rust binary from GitHub releases socketbin— improve platform detection for binary packages- add musl/Alpine Linux support for binary packages
build-infra— add github-error-utils for transient error handlingcli— use process.smol.mount() for full VFS directory extraction- add dependency updates to quality-scan skill + update deps
cli— add GH_TOKEN as fallback for GitHub authenticationcli— add explicit sfw command for Socket Firewallcli— add explicit pycli command for Python CLI invocationpython— unify Python CLI spawning with SEA and DLX supportbuild— add npm package download utilities for VFS bundlingskills— add validation and chain-of-thought to quality-scanscan— add socket-basics integration utilitiesclaude— add quality-scan skill for comprehensive code analysisdeps— add @socketbin packages to update script- migrate patch command to @socketsecurity/socket-patch@1.2.0 (#1042)
- add E2E test sharding and misc fixes (#1022)
- add alpm and vscode ecosystems, add scan type constants
- set scanType to socket_tier1 when creating reachability full scans
- add --silence flag to
socket fix - add --reach-lazy-mode flag for reachability analysis
telemetry— adding initial telemetry functionality to the clici— add force rebuild option to all workflow_dispatch workflowscli— standardize .version tracking across all extract scriptssea— improve build cache management and add local development modeconfig— use EditableJson for non-destructive config savingscan— add --reach-use-only-pregenerated-sboms flagfix— add --fix-version flag to override Coana CLI versionfix— add --ecosystems flag and rename --limit to --pr-limitfix— add --all flag to process all vulnerabilitiesdebug— add API request/response logging via SDK hookscli— add --reach-debug flag to enable verbose logging in the reachability (Coana) CLIbuild— leverage socket-btm releases for pre-compiled assetsscan— add reachability concurrency and analysis splitting flagspip— add socket pip3 command with auto-detection and context passingerrors— improve 403 error messages with command-specific permission guidancedx— standardize check runner output formattingdx— add .nvmrc and minimal quick-start guide- BREAKING:
build— improve setup script flags and logging build— add dead code elimination plugincli— optimize development workflow with caching and improved docscli-with-sentry— add package structure and build configurationbootstrap— add SOCKET_CLI_LOCAL_PATH support for testingcli— add supporting filescli— add new commandssfw— add Socket Firewall package manager wrapperssmol-builder— add granular checkpoint system and refactor loggerbootstrap— add Brotli compression for all bootstrap variantssmol— implement binary caching to avoid recompilation on post-processing failuresdlx— implement unified manifest for packages and binariesgit-hooks— make security checks mandatory, lint/test optionalscripts— add file validation checksvalidate— add bundle dependencies validationvalidation— add guard against link: dependencies and remove from rootpreflight— add @cyclonedx/cdxgen to background downloadsnlp— add progressive enhancement with ONNX Runtime stubci— add quantization level option to WASM workflowmodels— add INT8 quantization option for AI model buildsworkflows— add toggleable checkboxes for all build workflowsinstall— enhance installer with Socket branding and better UX- re-enable ONNX Runtime and add INT4-quantized AI models
build— add dependency-aware caching and binary build scriptsnode-smol-builder— implement VM-based bootstrap loader for async support- enhance socket build script with spinners and structured logging
- add comprehensive build script for socket package
- add shimmer effect to bootstrap spinner
- add spinner to bootstrap loading with withSpinner
build— add --platform and --arch flags for consistencybuild— add parallel builds and consolidate build systembuild— add intelligent caching to build systembootstrap— add IPC handshake support for subprocess detectionspawn— implement system Node.js detection with whichdlx— unify .dlx-metadata.json schema across TypeScript and C++ci— auto-update socketbin versions in provenance workflowcli— enhance error handling with network diagnostics and timeout errorsbootstrap— build SEA bootstrap in build scriptbootstrap— add SEA bootstrap for minimal SEA binariescli,cli-with-sentry— add LICENSE and CHANGELOG.md to packagesbuild— copy logos and data to packages during buildci— add npm@latest for trusted publishing supportcli— temporarily disable ONNX Runtime integrationpython— add Python CLI version tracking to build configurationpublish— query npm registry for latest @socketbin/* versionspublish— use base version from package.json for datetime versioningcli— add custom ONNX Runtime build package following yoga patternbootstrap— restore logger with lazy initialization supportbuild— add comprehensive Unicode property transformationsbuild— auto-generate socketbin spec for cache keyscompress— add spec string embedding for socket-lib cache keyscompress— implement self-extracting binary architecturedebug— add detailed HTTP request logging for failed API callsbootstrap— add Unicode property escape transforms for --with-intl=noneci— use Alpine Docker container for smol musl buildsci— add Alpine (musl) platform support to SEA and smol buildsfix— integrate provider pattern into PR operationsgit— implement GitLab provider with MR operationsgit— implement GitHub provider with PR operationsgit— add provider infrastructure for GitHub/GitLab supportcli— add markdown utility functions for consistent output formattingcli— implement markdown output for fix and optimize commandsfix— add comprehensive PR management and trackingsocket-fix— add batch PR flag for future implementationsocket-fix— add persistent GHSA tracking to avoid duplicate fixessocket-fix— add PR lifecycle logging and superseded PR detectionsea— add network retry, integrity checks, and freshness validationcli— add SHA256 checksum generation for build integritybuild— add network retry utility with exponential backoffbuild— auto-build bootstrap package when missingbootstrap— add system node detection and forwarding controlbootstrap— add system node detection and forwarding controlbootstrap— create shared bootstrap package for npm and smol buildssocket— add comprehensive builtin module mapping for smolsocket— add dual bootstrap build for SEA and smolci— build socket package bootstrap before SEA and smol buildsci— add stripped binary cache checkpoint for smol buildsbuild-infra— add preflight-checks runner for DRY build validationbuild-infra— add script-runner utilities for DRY monorepo operationsbuilders— add platform/arch arguments and use socket-lib parseArgssocket— add esbuild-based bootstrap implementationself-update— improve package manager detection and error messages- add install.sh for Socket CLI installation
ci— unify caching strategy across all build workflowsci— cache ONNX Runtime intermediate build artifactsci— add GitHub Actions grouping to WASM and SEA workflowsci— add Ninja installation for smol buildsnode-smol— add GitHub Actions grouping for verbose build stepsci— add concurrency control to build workflowssbom-generator— add TypeScript SBOM generator packageci— reuse cached binaries from build-socketbin.ymlci— add cache restoration and fallback WASM buildsci— add @socketbin build workflow with cachingci— add WASM build workflow with caching- add WIN32 shell support and update build infrastructure
node-sea-builder— add hash-based caching for SEA binariesnode-smol-builder— add hash-based caching for build artifactscli-ai— throttle model update checks to once per 24 hourscli— add hash-based caching to extraction scriptsbuild-infra— add extraction-cache utility for hash-based cachingsocketbin-cli-ai— add model update notifier with user promptsocketbin-cli-ai— add checkpoint-based incremental buildssocketbin-cli-ai— add complete build system with INT4 quantizationsocketbin— add @socketbin/cli-ai package with compression strategye2e— add interactive prompts and cache support for smol/sea binariessmol— make binary compression default with opt-outbuild-infra— add automated tool installer for cross-platform buildsmonorepo— add pnpm workspace catalog for Socket dependenciesnode-smol-builder— implement patch analysis with build-infra helpersbuild-infra— add patch analysis and conflict detectionbuild-infra— add build logging and checkpoint helperse2e— add auto-build support for binary E2E testse2e— add npm scripts for testing different binary typese2e— add comprehensive binary test suite for JS, smol, and SEAe2e— add environment files for comprehensive E2E testingbuild— add automated build tools installationenv— add RUN_E2E_TESTS environment variabledlx— add testable binary resolution patternenv— add system and LOCAL_PATH env modules with live VITEST modeos— add platform detection utilities for socketbin packagesregistry— add npm registry utilities for package downloadsbuild— complete WASM package build scriptsbuild-infra— add build environment and Rust builder modulestests— add case-insensitive env Proxy for Windows compatibilityscripts— add monorepo-aware update, type, and test scriptsscripts— add monorepo-aware lint, fix, and check scriptsscripts— add monorepo utility helpersbuild— add platform-specific binary size optimizationsecurity— prevent SIGUSR1 debugger signal handlingpatch— add default subcommand handlerconstants— add barrel file and fix test importspatch— enable patch command and fix testsconfig— add shared configuration architecture for monorepo- add Intl polyfill stub modules for CLI
- auto-strip AI attribution from commit messages
- add JS-only fallback release workflow for socket CLI
- register console and ask commands
- add interactive console command with Ink-based TUI
- add ASCII header banner utility with CI/VITEST plain text support
- implement SDK v3 file validation callback
- complete monorepo enhancements with all optional improvements
- add cli-sentry target for future @socketsecurity/cli-with-sentry package
- add all platform targets to build command
- add JSON and Markdown output support for manifest commands
- enhance workflows with monorepo support and configurable options
- add pre-publish validation to publishing workflows Add comprehensive validation to all three publishing workflows to prevent publishing broken packages. Created validation script that checks: - Package.json required fields and validity - Dist directory structure and files - Binary files and permissions - Data files presence - Production dependencies (no devDependencies) - Git status and tags - CLI bundle size sanity checks Workflow changes: - provenance.yml: Added validation after each of 3 package builds - publish-socketbin.yml: Added validation before main package publish - release-sea.yml: Added binary validation before GitHub release upload This prevents broken packages from reaching npm and users.
- add version consistency check script Create check-version-consistency.mjs to validate version numbers across package.json files before publishing. This ensures all packages are published with consistent versions. The script: - Checks main package.json version matches expected version - Optionally checks SEA npm package version (with warnings) - Exits with code 1 if critical version mismatches found - Provides clear colored output for CI workflows Referenced by .github/workflows/publish-socketbin.yml
- add ask mode demo and silence semantic model messages Add demo-ask-mode.mjs script that showcases natural language query translation across 6 categories with ~20 example queries. Remove semantic model loading messages since the model is optional and pattern matching works perfectly without it. The messages were noisy and gave the impression something was broken when it's actually working as intended.
- add esbuild configuration for CLI build Add esbuild configuration to replace Rollup bundler: - esbuild.cli.config.mjs: main configuration with plugins for package resolution - esbuild.cli.build.mjs: build script wrapper - esbuild-inject-import-meta.js: import.meta.url polyfill for CommonJS output This addresses template literal corruption issues in large bundles (>9MB) that occurred with Rollup. esbuild handles template literals correctly and produces faster builds without corruption.
- add module registration for --import flag Replace deprecated --loader with modern --import + register() API for Node.js 18+
- integrate MiniLM inference into socket ask command Updates handle-ask to use custom MiniLMInference engine instead of transformers.js. Implements hybrid semantic matching with three-tier progressive enhancement: pattern matching → word overlap → ONNX. Changes: - Replace transformers.js with MiniLMInference - Update cosineSimilarity to work with Float32Array - Use embedded ONNX from external/onnx-sync.mjs - Graceful degradation when ONNX unavailable
- add MiniLM model download and embedding scripts Scripts to download MiniLM model assets and embed them as base64 JavaScript for bundling. Follows yoga-layout WASM embedding pattern. - download-minilm.mjs: Downloads tokenizer and quantized ONNX model - embed-minilm.mjs: Embeds model as base64 in external/minilm-sync.mjs
- add MiniLM inference engine for semantic matching Implements direct ONNX Runtime integration with MiniLM model for semantic text understanding. Provides WordPiece tokenization, ONNX inference, mean pooling, and cosine similarity computation. Key features: - Direct ONNX Runtime with embedded WASM (no transformers.js wrapper) - Custom WordPiece tokenizer (pure JavaScript, 1-2ms per query) - 384-dimensional embeddings with mean pooling - Cosine similarity for semantic matching - SEA-compatible architecture with base64 WASM embedding
- add WordPiece tokenizer for ML model integration Implements pure JavaScript WordPiece tokenization for BERT/MiniLM models: WHAT IT IS: - Subword tokenization used by transformer models - Converts text → token IDs for ONNX Runtime - Zero ML dependencies, pure JavaScript HOW IT WORKS: 1. Basic tokenization (whitespace + punctuation splitting) 2. Greedy longest-match from vocabulary 3. Add special tokens ([CLS], [SEP], [UNK]) 4. Convert tokens to numeric IDs 5. Generate attention masks PERFORMANCE: - ~500KB vocab file (loaded once, cached) - ~1-2ms per query tokenization - Zero runtime ML overhead EXAMPLE: Input: "fixing vulnerabilities" Tokens: ["[CLS]", "fix", "##ing", "vulnerability", "##ies", "[SEP]"] IDs: [101, 8081, 2075, 23829, 2497, 102] FILES: - src/utils/wordpiece-tokenizer.mts - Core tokenizer implementation - src/utils/wordpiece-tokenizer.test.mts - Comprehensive test suite DOCUMENTATION: - Extensive inline comments explaining each step - Real-world examples from socket ask use cases - Links to original WordPiece and BERT papers
- add hybrid semantic matching for socket ask command Implements progressive enhancement for natural language understanding: Fast Path (instant): - Pattern matching with keyword detection - Compromise NLP for verb/noun normalization - Word-overlap matching with synonym expansion (~3KB semantic index) - Handles 80-90% of queries with zero ML overhead Fallback (50-80ms, high accuracy): - ONNX Runtime with MiniLM embeddings (planned) - Deep semantic understanding for ambiguous queries - Only loads when needed for remaining 10-20% edge cases Infrastructure: - scripts/llm/ directory for semantic tooling - scripts/extract-*-wasm.mjs for WASM bundling - Claude skills in ~/.claude/skills/socket-cli/ for IDE integration - Generic wasm-loader.mjs utility Architecture follows yoga-layout pattern for WASM embedding: - Base64 encode WASM at build time - Synchronous instantiation for SEA compatibility - Full control over loading and initialization
- enhance socket ask with compromise NLP library Add compromise for text normalization to handle: - Verb tenses: 'fixing' -> 'fix', 'scanned' -> 'scan' - Plurals: 'vulnerabilities' -> 'vulnerability' - Natural phrasing: 'Can you scan...' -> 'scan' Improves pattern matching accuracy by ~10-15% while maintaining fast response times (<100ms). Falls back gracefully if NLP fails. Size impact: +3MB (acceptable for dev tool)
- implement socket ask command with natural language processing - Add cmd-ask.mts with --execute and --explain flags - Add handle-ask.mts with pattern matching engine - Priority-based matching (fix/patch/optimize > scan/package > issues) - Extracts severity, environment, package names, dry-run mode - Confidence scoring for intent matching - Add output-ask.mts with rich formatted output - Color-coded query interpretation - Command preview with syntax highlighting - Detailed explanations of what commands do - Project context display (dependency counts) - Register command in src/commands.mts - Fix yoga-layout patch to remove restrictive exports Pattern matching maps natural language to Socket CLI commands: - 'fix critical issues' → socket fix --severity=critical - 'apply patches' → socket patch - 'optimize dependencies' → socket optimize - 'is express safe' → socket package score express - 'scan for vulnerabilities' → socket scan create
- enhance patch command functionality Add new patch discover, download, and status subcommands with improved UX
- register rm and cleanup subcommands in patch command Added cmdPatchRm and cmdPatchCleanup to the patch command's subcommand registry. This enables users to run socket patch rm and socket patch cleanup commands. All subcommands are now registered: - apply: Apply patches with backup creation - cleanup: Clean up orphaned backups - get: Download patch files - info: Show patch details - list: List all patches - rm: Remove patch and restore backups
- integrate backup system with patch apply Integrated Phase 1.1 backup system into patch apply command. Before applying any patch, createBackup() is called to store the original file contents. This enables safe rollback via socket patch rm. Changes: - Import createBackup from backup utilities - Add patchUuid parameter to processFilePatch - Create backup before copying patched file - Log backup creation and continue on backup failure - Pass patch UUID from manifest to backup system This completes the backup integration loop: - apply: creates backups - rm: restores backups - cleanup: removes orphaned backups
- add patch cleanup subcommand for backup management Implemented socket patch cleanup to manage orphaned patch backups. Supports three modes: - No args: Clean up orphaned backups (not in manifest) - UUID: Clean up specific patch backups - --all: Clean up all patch backups Uses Phase 1.1 backup system APIs: - listAllPatches() to find all backup UUIDs - cleanupBackups() to remove backup data Includes 7 comprehensive tests covering help, missing directory, cleanup modes, and all output formats.
- add patch rm subcommand with backup restoration Implemented socket patch rm
<PURL>to remove applied patches and restore original files from backups. Uses the Phase 1.1 backup system to restore files and clean up backups. Supports --keep-backups flag to preserve backup files after removal. Integrates with: - restoreAllBackups() to restore original files - cleanupBackups() to remove backup data - removePatch() to update manifest Includes 8 comprehensive tests covering help, missing PURL, patch not found, removal without backups, and all output formats. - add patch get subcommand Implemented socket patch get
<PURL>to download patch files from the .socket/blobs directory to a local directory for inspection. Files are copied with their directory structure preserved. Supports custom output directory via --output flag. Supports JSON and markdown output formats. Ready for tests to be added in next commit. - add patch info subcommand Implemented socket patch info
<PURL>to show detailed information about a specific patch. Displays all vulnerability details (GHSA IDs, CVEs, severity, descriptions), file changes with before/after hashes, and patch metadata (UUID, description, tier, license). Supports JSON and markdown output formats. Includes comprehensive tests covering help, missing PURL, patch not found, and all output formats. - add patch list subcommand Implemented socket patch list to display all patches from the manifest. Shows PURL, UUID, description, exported date, file count, vulnerability count, tier, and license for each patch. Supports JSON and markdown output formats. Includes comprehensive tests covering help, error cases, and all output formats.
- add handle test helper infrastructure Add setupStandardHandleMocks helper for handle function tests: - Automatic function name derivation from module paths - Module-level mock setup for vi.mock hoisting - Clear pattern for testing fetch + output orchestration - Comprehensive JSDoc with usage examples
- use unified runner for all test stages with Ctrl+O support - Use unified-runner for checks, build, and tests (not just tests) - Display "Press Ctrl+O to show/hide output" hint at start - Eliminates spinner artifacts in logs - Provides consistent Ctrl+O toggle experience throughout - Cleaner output with no leaked spinner frames
- improve test script output consistency and masking - Replace createSectionHeader with printHeader for consistent formatting - Mask build output with spinner instead of showing verbose logs - Only show build output on failure - Aligns socket-cli test runner with socket-registry style
- add unified runner with Ctrl+O toggle for test output - Added unified-runner.mjs for consistent interactive output control - Updated test.mjs to use unified runner for TTY sessions - Added test setup file to suppress debug output - Configured vitest to use setup file - Provides consistent Ctrl+O toggle behavior across socket-* repos
- add IPC validation module for inter-process communication - Add runtime validation for IPC messages - Implement type guards for IPC handshakes and stubs - Add helper functions for creating and parsing IPC messages - Ensure type safety for socket-cli inter-process communication
- add bordered input and lazy ink utilities - Add bordered-input.mts for styled terminal input - Add lazy-ink.mts for lazy loading ink components
- add interactive help system for better UX - Replace verbose --help output with interactive category selection - Support --help=category for direct category access - Categories: scan, fix, pm, pkg, org, config, ask, all, quick - Shows 'What can I help you with?' prompt with numbered options - Non-interactive terminals show category list with instructions - Maintains backward compatibility with --help-full for full output Examples: - socket --help # Interactive category selection - socket --help=scan # Show scan commands directly - socket --help=quick # Show quick start guide - socket --help-full # Show original full help
- add project context awareness and rich progress utilities - Add project context detection for package managers and frameworks - Add rich progress indicators for better UX during long operations - Create foundation for Claude CLI-like enhancements - Support for multi-progress bars, spinners, and file progress - Auto-detect npm/yarn/pnpm and provide contextual suggestions
- add trusted publisher verification script - Check if all @socketbin packages exist on npm - Verify provenance attestations if present - Check GitHub workflow configuration - Verify NPM_TOKEN secret (if accessible) - Provide clear status and next steps Run with: node scripts/verify-trusted-publisher.mjs
- add placeholder packages for @socketbin namespace - Create placeholder packages at v0.0.0 for all 6 platforms - Add script to generate placeholder packages - Add script to publish all placeholders at once - Add verification script to check packages on npm registry These placeholders are needed to enable trusted publisher configuration. Real binaries will be published at v1.x after trusted publisher is set up.
- implement @socketbin binary distribution system - Add package generator script for creating @socketbin/* packages - Create dispatcher script that selects correct platform binary - Add GitHub Actions workflow for building and publishing with provenance - Update socket package to use optionalDependencies instead of postinstall - Remove install.js in favor of npm's built-in optional dependency handling This new approach eliminates postinstall failures and simplifies distribution
- add catastrophic delete protection to bootstrap remove() - Add inline remove() function with safety checks similar to del package - Prevent deleting cwd or directories outside SOCKET_HOME - Replace all fs.unlink() calls with safe remove() - Protects against accidental system-wide deletions - Can be overridden with force option if needed
- add affected test runner for faster test execution Implements intelligent test selection based on git changes to speed up local development and precommit hooks. Maps source files to their corresponding test files, running only affected tests when possible. Key features: - Detects changed/staged files using git utilities - Maps commands to co-located test files - Maps utils to test files in src/utils/ and test/unit/utils/ - Core files (cli, constants, types) trigger all tests - Supports --staged, --all, --force, and --coverage flags - Builds project automatically if needed
- add experimental bootstrap loader for stub distribution Simple Node.js loader that checks for ~/.socket/_socket and delegates. Foundation for future bootstrap architecture improvements. Not yet integrated with build system.
- add build dependency checker and stub bundle verification - check-build-deps: Verifies build tools, offers UPX installation - verify-stub-bundle: Ensures bootstrap contains only Node builtins - Both support cross-platform (macOS, Linux, Windows)
- add bootstrap stub update capability to self-update command - Add checkAndUpdateStub() to update bootstrap stub during self-update - Check for stub updates even when CLI is up to date - Use stub path from IPC handshake to locate stub binary - Create backups and handle rollback for stub updates - Update both CLI and stub binaries in single self-update operation
- add centralized Ink and React imports wrapper Create src/utils/ink.mts to centralize Ink, React, and InkTable imports with proper tsgo workarounds. Add src/external/ink-table wrapper for proper ESM/CommonJS interop. This eliminates the need for @ts-ignore comments in every TSX file.
- add comprehensive memoization utilities Added full-featured memoization system for caching function results and optimizing expensive computations. Memoization Features: - memoize() for sync functions with configurable caching - memoizeAsync() for async functions with promise deduplication - memoizeWeak() using WeakMap for garbage-collectable object keys - once() for single-execution functions - memoizeDebounced() combining memoization with debouncing - LRU cache eviction when maxSize exceeded - TTL expiration for time-limited caching - Custom key generators for flexible cache keys - @Memoize decorator for class methods Cache Management: - Configurable max cache size with LRU eviction - TTL-based expiration - Access count tracking - Cache hit/miss debugging (DEBUG=cache) - Failed promise cleanup (errors not cached) - Concurrent call deduplication for async functions Test Coverage: - 20 tests covering all functionality (all passing) - Basic memoization with various argument types - Custom key generators - LRU eviction - TTL expiration - Async function handling - Concurrent call deduplication - Error handling - WeakMap garbage collection - once() single execution Usage Examples: - Simple: const fn = memoize((x) => x * 2) - With options: memoize(fn, { maxSize: 100, ttl: 60000 }) - Async: const fn = memoizeAsync(async (id) => await fetchData(id)) - Once: const init = once(() => loadConfig()) - Weak: const fn = memoizeWeak((obj) => transform(obj)) Technical Details: - Zero overhead when DEBUG!=cache - Proper TypeScript generics - LRU access order tracking - High-resolution timestamps - Promise caching prevents duplicate API calls - WeakMap enables garbage collection
- add comprehensive performance monitoring utilities Added full-featured performance monitoring system for identifying bottlenecks and optimizing CLI execution. Performance Monitoring Features: - perfTimer() for timing operations with metadata - measure() and measureSync() for function execution timing - perfCheckpoint() for tracking progress through complex operations - trackMemory() for heap usage monitoring - Performance metrics collection (operation, duration, timestamp, metadata) - getPerformanceSummary() with count, avg, min, max, total statistics - generatePerformanceReport() for formatted output - Automatic cleanup and metric aggregation Integration: - Integrates with DEBUG=perf environment variable - No-op when perf tracking disabled (zero overhead) - Compatible with existing debug logging system - Works with debugFn for console output Test Coverage: - 21 tests covering all functionality (all passing) - Timer operations with metadata - Async and sync function measurement - Error handling and metadata tracking - Summary statistics calculation - Checkpoint and memory tracking - Report generation Usage Examples: - Simple timing: const stop = perfTimer('op'); stop() - Function measurement: const { result, duration } = await measure('op', fn) - Checkpoints: perfCheckpoint('phase-1', { count: 100 }) - Memory tracking: const mem = trackMemory('before-operation') - Summary: printPerformanceSummary() Technical Details: - Uses performance.now() for high-resolution timing - Rounds durations to 2 decimal places - Groups metrics by operation name - Exports all metrics for external analysis - Type-safe with PerformanceMetrics interface
- add intelligent caching strategies and comprehensive tests Added smart caching strategies and comprehensive test coverage for new features. Intelligent Caching Strategies: - Endpoint-specific TTL based on data volatility - Package info: 15min (stable), Issues: 5min (volatile), Scans: 2min (very volatile) - Org settings: 30min, User info: 1hr (most stable) - getCacheStrategy() for automatic TTL selection - shouldWarmCache() for critical data preloading - calculateAdaptiveTtl() for frequency-based TTL adjustment - Cache warming support for faster initial responses Test Coverage: - 23 tests for cache strategies (all passing) - Strategy selection for different endpoint patterns - TTL recommendations based on data characteristics - Cache warming decisions - Volatility detection - Adaptive TTL calculations - 14 tests for table formatting (all passing) - Bordered table rendering with box-drawing characters - Simple table rendering without borders - Column alignment (left, right, center) - Color function application - Width calculation with ANSI codes - Missing value handling - Dynamic vs fixed column widths Technical Details: - Pattern matching with glob-style wildcards - Debug logging integration for cache operations - Minimum TTL enforcement (30s) for adaptive caching - Maximum 50% reduction for frequently accessed data
- Enhanced error handling with recovery suggestions Add comprehensive error types with actionable recovery information: - AuthError: Authentication failures with login instructions - NetworkError: Connection issues with retry guidance - RateLimitError: API quota exceeded with wait times and upgrade suggestions - FileSystemError: File operations with code-specific recovery (ENOENT, EACCES, ENOSPC) - ConfigError: Configuration issues with setup instructions Improvements: - Each error type includes contextual recovery suggestions - Recovery suggestions displayed in terminal output with visual hierarchy - JSON output includes recovery array for programmatic consumption - Error display enhanced with cyan 'Suggested actions' section - 41 comprehensive tests covering all error types and recovery utilities Benefits: - Users get immediate, actionable guidance when errors occur - Reduces support burden with self-service recovery steps - Better UX with helpful suggestions vs generic error messages - Consistent error handling patterns across the codebase
- Add command registry infrastructure Add complete command registry system with: - Type-safe command definitions with flags, validation, and hooks - CommandRegistry class for registration and execution - Koa-style middleware composition - Flag parsing (string, boolean, number, array types) - Required flag validation and custom validators - Automatic help text generation - Before/after hooks for command lifecycle - Plugin system for extensibility - 17 comprehensive tests (all passing) Benefits: - Declarative command definitions vs imperative code - Type-safe with full TypeScript support - Self-documenting via auto-generated help - Middleware for cross-cutting concerns - Testable and composable Architecture ready for migration but not yet integrated into CLI entry point. Existing meow-based system continues to work unchanged.
- add comprehensive test utilities Add mock-helpers.mts with SDK/API mocking utilities Add environment.mts with test setup and cleanup helpers Add fixtures.mts with standard test data configurations Add constants.mts with common test values Add index.mts for convenient re-exports
- add core utilities for types, messages, result handling, and logging Add BaseFetchOptions type for consistent SDK options Add centralized error message templates in messages.mts Add result validation utilities with requireOk, map, chain functions Add command-scoped logger with context for better debugging
cli— use direct env reads for HOME in 5 commandsci— complete dependency caching for all test jobsci— add dependency caching to GitHub Actionspublish— optimize CLI build and consolidate platform definitionssea— parallelize binary injection for 8x faster buildscli— add Node.js memory allocation flags for large buildsscripts— optimize build processcli— defer registryUrl lookup until neededsmol— use vm.compileFunction() and remove internal path remappingci— implement critical workflow optimizationsci— add Emscripten SDK and pip caching to build-sea workflowci— add Emscripten SDK and pip package caching to WASM workflow- optimize CI and test performance
- remove lazy-loading of bun lockfile parser
ci— add caching to build-deps jobsci— increase max parallel builds to 6 for SEA and smol workflowsci— add pip cache for Python dependencies in AI models buildci— optimize runner allocation and switch to Ninjaci— optimize binary builds with ccache and faster runnerswasm— switch to single-threaded ONNX Runtime varianttest— maximize thread pool based on CPU countbuild,test,ci,docs— apply socket-sdk-js optimizations across all phases
build— repair createHash import and drop unpublished lib-stable external/semver subpathbuild— restore pipeline modules and exports the dead-code sweep removed while still importedbuild— restore build-pipeline.mts — scripts/build.mts still imports runPipelineClici— refresh external-tools pins to fleet data formatconfig— repo.type is mono, not monorepodeps— bump vulnerable packages to soaked patched versionssea— repoint build-sea/test-sea imports at sea-build-utils dirdeps— pin rolldown to soaked 1.0.3, matching the fleet baselinelint— migrate socket-hook markers to socket-lint prefixscripts— delegate all test scopes to per-package in no-config workspacesdeps— migrate source to lib-stable 6.0.7 APIscripts— make fleet test runner monorepo-safe and drop pnpm execscripts— import logger in sync-checksums so log calls don't ReferenceErrorhooks— repoint commit-msg husky shim to .git-hooks/fleet/hooks— repoint husky shims to .git-hooks/fleet/ after segmentationdebug,git— redact GitHub token in debug log; use debugNs for level namespacesmcp— bind unauthenticated HTTP transport to loopback + cap POST bodyscripts,format— repair migration-orphan imports/paths + format-script scopedeps— bump vitest to 4.1.6 to clear GHSA-5xrq-8626-4rwphooks— declare shell-quote dep so _shared parser resolvestsconfig— point extends at .config/fleet/tsconfig.base.jsonbuild— migrate remaining external-tools.json tools to platforms schemabuild— migrate pnpm external-tools entry to platforms schemalint— revert colocate work in packages/cli/src — fleet rule requires exportrich-progress— restore inadvertently-deleted file + v6 leaf importrich-progress— inline socket-hook marker so logger-guard sees it on the right linebuild— give each downloaded asset its own subdir to avoid .version racemcp/transport-http— drop| undefinedfrom McpHandleRequest's auth fieldlint— convert file-scope oxlint disables + clear other violationspackageManager— bump pnpm@11.0.8 → pnpm@11.1.2- stop oxfmt from reformatting wheelhouse-schema.json
scripts/check-prompt-less-setup— drop never-used writeFileSync + isLinuxdeps— restore -stable catalog aliases for self-named fleet packageslint— clean lint debt in packages/cli/scripts + srctypes— restore explicit-undefined on AuthenticatedRequest.authtypes— resolve 4 tsgo errors in clivitest— drop orphan base config + fix stale isolate commentscripts— restore spawnSync import in bootstrap-firewall-depsdeps— bump hono to 4.12.18, fast-uri to 3.1.2 for CVE patcheslint— dlx test polish — import-type, max-file-lines, sorttypes— resolve noUncheckedIndexedAccess + noUncheckedSideEffectImportslint— generate-report.test — max-file-lines legitimate bypasslint— cmd-manifest-cdxgen — exported helpers + cached for-looplint— telemetry — prefer-function-declaration + cached-for-looplint— mark Set-iteration for-of as intentional in 3 siteshook— mark progress-bar stderr writes as intentionallint— clear remaining socket/* rule violations in cli packagelint— scripts and package-builderlint— cache array.length in build-infra for-loopssync— cascade prefer-cached-for-loop let/const preservation patchlint— sort-source-methods - reorder 20 src files + oxfmt drifttests— restore vi.mock named exports for node:fs / node:os after import refactorlint— autofix sort-source-methods (13 files) + cascade canonical script fixeslint— close out non-blocked socket-cli rulestypes— no-explicit-any — final 29 src files (1-site fixes, brings count to 0)types— no-explicit-any — 11 src files, mostly 2-3 sites eachtypes— no-explicit-any — 7 src files (pull-request, update-manifest, scan-from-github, lockfile-readers, errors, package-alert, shallow-score)types— no-explicit-any — second-pass test files for return / tuple positionstypes— no-explicit-any — top 6 src files (logger, api-wrapper, builder, meow, api, simple-output)types— consistent-type-imports — hoist 30 inline import() annotations across 19 test filestypes— no-explicit-any — replace any with unknown in test files (batch 3/3)types— no-explicit-any — replace any with unknown in test files (batch 2/3)types— no-explicit-any — replace any with unknown in test files (batch 1/3)imports— node-builtin — inline-disable 6 test files using fs as valuetypes— consistent-type-imports — hoist 29 inline import() annotations across 15 test filestypes— consistent-type-imports — hoist 29 inline import() annotations across 15 test filestypes— consistent-type-imports — hoist 16 inline import() annotations across 10 test filestypes— iocraft — add namespace import for ComponentNode type castimports— node-builtin — remove dead fs imports in 5 test filestypes— consistent-type-imports — hoist 12 inline import() annotations across 5 test filesimports— node-builtin — 7 files converted to named importstypes— consistent-type-imports — hoist inline import() in sdk-test-helpers.mtsregex— sort-regex-alternations — 8 rewrites + 1 order-significant disabletypes— consistent-type-imports — hoist inline import() in iocraft.mtstypes— consistent-type-imports — hoist inline import() in spawn-node.mtstypes— consistent-type-imports — hoist inline import() in types.mtsimports— node-builtin — 5 files converted to named importsimports— node-builtin — 6 files converted to named importslint— sort-named-imports — inline-disable intentional domain-grouped barrel importlint— max-file-lines — file-level bypass on 86 oversized fileslint— no-fetch-prefer-http-request — inline-disable 5 dev-script fetches that need raw Responselint— apply 2nd-pass oxlint autofixes — sort-source-methods reorder 3 fileslint— personal-path-placeholders — file-level disable on fixture tests + replace example usernames in src commentslint— prefer-exists-sync — rewrite 2 fileExists helpers + inline-disable legitimate metadata readsoxlint— rewrite overrides patterns as /scripts/ etc.lint— export-top-level-functions — collapse 5 export-block aggregatorslint— apply oxlint autofixes — export-top-level-functions / prefer-exists-sync / prefer-node-builtin-imports / sort-equality-disjunctions / prefer-undefined-over-nullno-status-emoji— cascade rule self-disable + bypass scripts/testslint— re-cascade canonical oxlint plugin rules — undo self-corruption- lint --fix autofix pass + cascade canonical check-paths.mts
tests— align 39 assertions with null→undefined fliptypes,quality— revert Object.create(undefined) regression + finish null→undefined flipcli— registermcpin canonical bucketed-commands setdeps— bump hono via override to ≥4.12.16 (CVE patched)hooks— release-workflow-guard — multi-root dry-run resolutionhook— release-workflow-guard — derive project dir from script pathhooks— tighten npx-scanner regex to skip identifier/key contextsdeps— override ip-address >=10.1.1 (GHSA-v2v4-37r5-5v8g)hooks— anchor hook commands + project paths to $CLAUDE_PROJECT_DIRtest— repair four CI-failing assertions on maindeps— regenerate pnpm-lock.yaml for catalog driftcli— stop socket cdxgen from silently shipping empty-components SBOMs (#1266)cli— error messages in env/ + constants/ + sea-build scripts (#1258)cli— error messages in utils/ misc (flags, fs, git, npm, promise, terminal) (#1260)cli— error messages for utils/update + utils/command + error library migration (#1257)cli— error messages in utils/dlx/ (#1256)cli— error messages in commands/ (14 commands + their tests) (#1255)cli— align test/ error messages with 4-ingredient strategy (#1259)cli— return org slug, not display name, from org resolution (#1232)deps— bump nanotar 0.2.0 → 0.2.1 to patch path traversal (CVE-2025-69874) (#1250)debug— log structured HTTP error details instead of raw response (#1233)test— pass --passWithNoTests to vitest (#1240)scan— surface GitHub rate-limit errors in bulk repo scan (#1235)fix— validate target directory and detect misplaced IDs (#1227)api— include request path in API error messages (#1224)api— distinguish 401 (auth failure) from 403 (permissions) (#1226)scan— respect projectIgnorePaths from socket.yml (#1225)ci— replace close/reopen hack with workflow_dispatch for bot PRs (#1210)build— improve asset download resilience against rate limits (#1201)config— align .npmrc and pnpm-workspace.yaml for pnpm v11 (#1198)hooks— normalize platform keys and strip host prefix from repository (#1194)hooks— use strings for binary file scanning in pre-push (#1196)hooks— update zizmor repo from woodruffw to zizmorcore (#1191)deps— bump vite to 7.3.2 (security) (#1168)ci— harden weekly-update — allowedTools, two-phase update, diff validation (#1159)- move minimum-release-age to pnpm-workspace.yaml (#1158)
build— fix runtime bugs in build scripts (#1148)- upgrade handlebars to 4.7.9, fix pre-push hook (#1134)
- upgrade brace-expansion to 5.0.5 (CVE-2026-33750) (#1132)
ci— rebuild weekly-update.yml with proper YAML and features- harden GitHub Actions workflows (#1129)
ci— update pnpm/action-setup to Node 24 (58e6119)skill— update updating skill to use pnpm run update and check --allci— add timeout-minutes and shell declarations to workflowsci— add explicit shell: bash declarations to provenance workflowtypes— remove unused import and fix context testssecurity— make missing SHA-256 checksums a hard errorci— add complete stub package with JS implementation for iocraftci— create stub packages before pnpm installci— setup pnpm before node to enable cachetypes— resolve TypeScript type errors in iocraft and test helperstui— fix border rendering in iocraft column layoutsdeps— remove stale restore-cursor patchdeps— remove stale React/Ink dependencies after iocraft migrationtest— replace unsafe fs.rm with safeDeletecli— improve cache coherency and notification handlingcli— handle undefined returns from getMajor in optimizesecurity— address critical security vulnerabilitiescli— invalidate token cache on login/logoutcli— correct unreachable error branch in scan-diffiocraft— critical publishing workflow fixespublish— use separate versions for cli and iocraft ecosystemsiocraft— use independent versioning starting at 1.0.0-pre.0cli— transform yoga-sync.mjs to remove top-level await for CJS- use 0.0.0 for placeholder version (matches existing pattern)
- properly disable dependabot (#1119)
publish— rename workflow to provenance.yml for trusted publishingpublish— restore socket package and fix pathsci— read base version from cli-package templatepublish— add missing check-version-consistency script and update docssfw— use separate versions for SEA and npm CLI distributions- address quality scan findings (Round 1)
dry-run— show computed query parameters in read-only commandscli— enhance fix dry-run to show computed detailscli— improve optimize dry-run and remove unused logger importsquality-scan— remove socket-btm cross-project referencescli— replace broken --dry-run with meaningful preview outputtest— inject inlined env vars in test setup for e2e testsci— remove integration tests job (no integration tests exist)ci— simplify CI workflow and remove references to non-existent directoriesci— use pnpm/action-setup to read packageManager from package.jsonquality— add try-catch for JSON.parse in build scriptsquality— add defensive checks and fix Windows ARM64 Python detection- quality scan fixes - NaN validation, logging conventions, docs
sea— use relative paths in sea-config and update SDK- remove cross-repository updates from quality-scan skill
sea— update Trivy to v0.69.2sea— use win32 platform keys in external-tools-platformsvfs— update mount type signature to asyncPromise<string>sea— fix sfw extraction from VFS with node_modules structuresea— add Socket Firewall (sfw) to VFS bundlingscan— correct policy strictness comparison in alert aggregationhooks— check only new commits in pre-push, not all since releasehooks— use portable for loop instead of process substitution in pre-pushcli— address quality scan findings round 10package-builder— correct dependencies for cli-with-sentry templatecli— restore 'as unknown as' pattern in type assertionscli— handle negative time deltas in msAtHome functioncli— add defensive optional chaining in getHighestEntryIndexcli— address remaining round 17 low priority issuescli— address round 17 quality scan findingscli— improve type safety by replacing unsafe type assertionscli— remove globalThis indirection in update notifiercli— improve Coana output parsing to handle empty linescli— add HTTP request timeouts to prevent indefinite hangscli— restore and fix handle-optimize.test.mtscli— resolve TOCTOU race conditions in file cleanupcli— replace Math.random() with fixed delay in preflight downloadscli— address quality scan findings round 9cli— address quality scan findings round 8cli— prevent unbounded Map growth in inflight trackerscli— code style consistency - catch parameter naming and type safetycli— add missing lru-cache dependencycli— address quality scan findings round 4 (part 2) - lock detection and race conditionscli— address quality scan findings round 4 (part 1)cli— address quality scan findings round 3cli— capture timestamp at function entry for accurate TTLci— add required .env.precommit for pre-commit hooksci— improve workflow reliability and security validationcli— add input validation and bounds checkingcli— resolve race conditions and improve locking mechanismscli— resolve memory leaks and resource cleanup issuescli— fix getMaxOldSpaceSizeFlag default calculationhooks— add prerequisite checks to pre-commit hookcli— address quality scan findings round 11cli— address quality scan findings round 10cli— address quality scan findings round 9cli— address quality scan findings round 8cli— address quality scan findings round 7cli— address round 6 quality scan findingscli— address round 5 quality scan findingscli— address quality scan findings (round 4)cli— address quality scan findings (round 3)cli— address quality scan findings (round 2)cli— address quality scan findings across codebasecli— inject external tool versions in integration test runnerscripts— use absolute paths for validation scripts in check.mjstypes— resolve TypeScript errors in spawn usage and unused importstypes— resolve TypeScript errors in quality scan fixesbuild— resolve TOCTOU races and cache invalidationcli— improve type safety in spec parsing and overridesscan— resolve critical bugs in scan output handlersbuild— remove redundant warning emojis from logger.warn callsdeps— always update Socket packages in update script (#1059)deps— add restore-cursor signal-exit v4 compatibility patchdeps— update @socketsecurity/lib to v5.5.3 and add signal-exit v4 compatibility patchesdeps— update Socket packages regardless of taze result- prevent heap overflow in large monorepo scans (#1041)
- remaining fixes from PR 1025 (#1027)
- ensure build directory exists before writing yoga placeholder
- remove unused silence parameter from FetchOrganizationOptions type
- update extract scripts for corrected socket-btm asset names
- implement findAsset locally, remove non-existent import
- exit with code 1 when socket ci finds blocking alerts
security— disable automatic caching in setup-node to prevent cache poisoningsecurity— resolve artipacked and docker security vulnerabilitiessea— use unique cache directories for parallel binject buildssea— add exit code checking for binject spawnbuild— use bracket notation for TypeScript index signaturesbuild— add GitHub API authentication to avoid rate limitsdeps— Remove http2 module dependency from @sigstore/signcli— add per-platform caching for parallel SEA buildsbuild-infra— add GitHub token authentication to API requestsbuild-infra— Add GitHub API headers to httpRequest callsglob— add dot:true to match dotfiles and dot directoriesoptimize— remove Node.js version filter from manifest entriessea— use toUnixPath for Git Bash tar compatibilitysea— use current Node.js process for SEA blob generationsea— update binject command and node-smol URL formatdebug— use correct debug functions with proper namespacingscan— use Octokit for GitHub API calls with proper error handlingci— add Node.js and pnpm setup immediately after checkout in all workflowssea— compute rootPath in getBinjectPath functionbuild— use yoga-sync.mjs from socket-btm and integrate binjectcli— resolve socket-lib external paths at any nesting depthbootstrap— remove non-existent polyfill imports and fix build errorsfix— add ecosystems support to coana CLI callsfix— add --limit as alias for --pr-limitflags— make --exclude and --include visible in socket fix commanddlx— support Coana CLI binary execution via SOCKET_CLI_COANA_LOCAL_PATHdocs— remove hardcoded personal paths and realistic API key exampleshooks— limit pre-push AI attribution check to commits since latest release- upload manifest files relative to target for coana-fix and perform-reachability-analysis
self-update— implement bootstrap binary path via IPC handshakeapi— improve CVE to GHSA conversion caching and error messagingcli— resolve --limit flag not working in local modefix— improve PR creation logic and branch lifecycle managementdlx— pin Coana to exact version without tilde prefixalerts— respect SOCKET_CLI_API_TOKEN environment variabletest— resolve flaky TTL boundary test by mocking Date.now()build— inline environment variables to prevent package.json errorsshadow— use static imports for shadow bins instead of dynamic requirespawn— add which() resolution for command spawnsdeps— fix bin entries and standardize engine requirementsui— change error badge text from red to white on red backgrounddeps— resolve ANSI bundling compatibility issuesbootstrap— use consistent naming for published build flagdev— improve fresh clone developer experiencebuild— fix bundle dependencies validation and add missing depsbuild— add TypeScript dependency and fix socket-lib bundlingbuild— update pnpm and fix CLI build with socket-lib 3.3.2test— fix test infrastructure and ensure build before test:allbuild— fix bundle dependencies validationsetup— verify gh CLI is accessible after installationcli— add missing subcommands to help menu validationhooks— improve AI attribution detection in pre-push hookhooks— use printf for colored output in pre-push hookworkflows— resolve all zizmor security findingssocket— correct package.json metadata and build scriptsocket— add missing version defines to bootstrap build configcli— add src to files array for bin entrycli— rename duplicate dev script to dev:watch for claritytypes— resolve TypeScript errors in package manager commandshooks— improve git hook compatibility and formattingsmol-builder— fix spawn import in compress-binary scriptsmol-builder— fix smokeTestBinary API mismatchsmol-builder— standardize brotli2c naming to socketsecurity_ prefixsmol-builder— convert remaining patches to standard unified diff formatsmol-builder— convert polyfill patches to standard unified diff formatsmol-builder— regenerate polyfill patches with real git hashessmol-builder— replace fs.rm with safeDelete for secure deletionsmol-builder— replace remaining rm calls with fs.rmsmol-builder— replace cp with fs.cp for file copy operationssmol-builder— add readdirSync back to fs importssmol-builder— replace remaining mkdir calls with safeMkdireslint— enable no-undef rule for script filessmol-builder— use fs.method() pattern for all fs.promises callssmol-builder— replace mkdir with safeMkdirsmol-builder— copy bootstrap loader to lib/internal before compilationsmol-builder— correct brotli2c patch line numbers for pristine Node.js v24.10.0sea-builder— remove erroneous closing brace causing syntax errorsmol-builder— copy brotli header to src directorysmol-builder— update hardcoded patch reference to use numbered prefixtest— correct import path for confirm promptbootstrap— use major version only for CLI download specsmol— implement robust cross-platform strip with capability detectionsmol— use platform-specific strip flags for binary optimizationsmol— use shell for execCapture and enable fail-fast for buildsbootstrap— show Socket CLI version instead of Node.js versionbootstrap— skip preflight on --version for instant responsesmol— skip CLI bootstrap for basic Node.js operationsci— make WASM optional in SEA builds with graceful fallbackci— remove ai-cache-valid references from build-sea workflowci— comment out socketbin-cli-ai references in build-sea workflowci— update ONNX Runtime artifact verification to check for .mjs filesonnx— add existence checks to patch verificationonnx— verify wasm_post_build.js patch in cache validationonnx— clean stale cache after GitHub Actions restorationonnxruntime— patch wasm_post_build.js in both source and build directoriesbootstrap— remove unnecessary empty log after spinner completestest— reduce thread count on macOS CI to prevent SIGABRTtypes— resolve exactOptionalPropertyTypes issue in UpdateStoreupdate— only show content-type warning in debug mode on parse failuretypes— correct parameter types for SDK method callstypes— add explicit type parameters to handleApiCall callstypes— update handleApiCall signature for SDK v3 compatibilitytypes— revert to use SDK v3 method names in type referencestypes— update SDK operation names to match API typesdeps— update all packages to use catalog for @socketsecurity/liblint— fix all lint errors and update dependenciesbuild— externalize Socket dependencies and add bundle validation test- update for @socketsecurity/lib 3.0.5 compatibility
build— use default export workaround for CommonJS imports with --import flagtest— resolve TypeScript errors and test failures in NLP modulessmol— use Module.prototype.require.bind for virtual modulesmol— use Module.createRequire for proper module contextonnx— patch wasm_post_build.js to handle modern Emscriptenbootstrap— correct stream/promises module path for smol buildsci— remove expression from build-models job namemodels— correct --all flag logic to build both modelsci— build all AI models in workflowmodels— check for all expected ONNX files during conversionmodels— fix method variable scope in quantization fallbackci— remove invalid job-level matrix conditions from workflowsonnxruntime— remove EXPORT_ES6=0 patch for threading compatibilityonnxruntime— enable threading and SIMD for v1.21.1 compatibilityci— mark ONNX Runtime WASM build as non-blockingmodels— update INT4 quantization API for onnxruntime 1.20+ci— install optimum[onnxruntime] for ONNX model exportonnx— remove ES module type from onnxruntime package.jsonsocket— remove bootstrap-smol.js from npm package buildpatch— remove unused imports after duplicate logging removalpatch— remove duplicate output logging to fix markdown test flakinesspath— handle UNC paths correctly on Windowspath— add Windows validation for Unix-style paths in findNpmDirPathSyncwasm— update INT4 quantization to use matmul_nbits_quantizer APIci— pin onnxruntime>=1.20.0 to ensure INT4 quantization supportci— upgrade onnxruntime and add INT4 quantization toolsci— uncomment ONNX Runtime build steps to fix bash syntax errorbootstrap— eliminate spurious error message on successful CLI execution- improve bootstrap error handling
completion— resolve CLI package root correctly for tab completion scriptscan— flatten SDK options and make repo parameter conditional- restore v1.x environment variable fallbacks and EEXIST handling
smol— enable code cache for brotli decompression support- run build before verify in socket package
- inject MIN_NODE_VERSION in bootstrap esbuild configs
- use logger.fail for error messages in verify script
- read CLI version from socket package.json during build
cli-with-sentry— add missing esbuild config for shadow-npm-injectcli-with-sentry— add missing shadow-npm-inject build stepbuild— skip onnxruntime build (temporarily disabled)gitignore— allow docs/build directory without requiring -f flag- resolve TypeScript errors after nodeDebugFlags removal
- remove nodeDebugFlags references
build— align platform/arch flags in build-all-binariesbuild— disable minifySyntax across all esbuild configssocket— disable minifySyntax to prevent async function boundary corruptionci— align smol cache keys with build-smol.yml in publish-socketbin.ymlci— use SEA binary cache from build-sea.yml in publish-socketbin.ymlsbom-generator— resolve exactOptionalPropertyTypes type errorstest— use proper function syntax for Vitest constructor mockslint— resolve lint errors and remove dead getInternals codenode-sea-builder— add missing crypto importbootstrap— improve error handling for CLI download failurescli— update getBinCliPath to use dist/index.js instead of bin/cli.jsenvironment— remove unused createRequire importenvironment— lazy-load bun lockfile parserinstall— download from npm registry instead of GitHub releasesprepare— remove dotenvx wrapper from husky prepare scriptworkflow— specify correct build target for cli-with-sentryworkflow— update JS-only fallback validationcli-with-sentry— use dist/index.js and validate cli.js.bzcli-with-sentry— use socket-with-sentry bin namecli-with-sentry— move @sentry/node to dependenciesci— validate yoga WASM cache instead of building on missci— publish from package directories and build yoga WASM on cache missci— replace obsolete external cache with yoga-layout WASM cachescripts— update dist validation to check for index.js and cli.js.bzscripts— update pre-publish-validate to accept package pathscripts— remove duplicate colors declaration in pre-publish-validateci— use 'pnpm run build' instead of non-existent 'build:dist'packages— run pnpm pkg fix to normalize package.json fieldssocketbin— add repository field to all package.json filesci— add --tag latest to all npm publish commands for prerelease versionsci— use semver to extract X.Y.Z from package version before appending timestampscripts— skip socketbin-cli-ai version check (not published by workflow)scripts— skip root package.json check for socketbin versionsci— install dependencies before version consistency checkci— use bash shell for verify binary step on Windowsci— skip smol build when method=sea and use bash shell for Windows compatibilityci— use 2-core runners in publish-socketbin for better availabilityci— comment out ONNX runtime in build-sea workflowci— correct ONNX package paths in build-sea workflowci— correct SEA builder package name in publish-socketbinci— add CLI build step before SEA binary build in publish-socketbinscripts— prepublish-socketbin should create bin/socket not bin/clici— align publish-socketbin binary paths with build-sea namingci— upgrade actions/cache to v4.3.0 in publish-socketbin workflowscripts— improve type check error output in check scriptcli— add missing INLINED_SOCKET_CLI_PYCLI_VERSION to ENVonnxruntime— correct EXPORT_ES6=0 to output .js files instead of .mjsonnxruntime— add EXPORT_ES6=0 patch and require shim for WASM buildtest— fix scan create tests to use valid directory targetsonnx— disable WASM threading and patch cmake to fix MLFloat16 build errorstest— fix self-update tests by mocking canSelfUpdate and cleaning up leftover directoriesbuild— add missing INLINED_SOCKET_CLI_CDXGEN_VERSION to esbuild configonnxruntime— enable WASM threading to fix MLFloat16 build errorsbootstrap— remove logger usage from smol bootstrap for early initializationtests— fix GitLab provider mock constructortests— fix npm-config mock constructor to work with 'new' operatorscan-reach— handle empty string and undefined outputPath properlycli— inline build-time constants with post-bundle replacement pluginbuild-infra— escape regex patterns for string literal context in Unicode transformonnxruntime— pass WASM_ASYNC_COMPILATION via CMake definesci— use package version for WASM workflow cache keysci— use package version for ONNX Runtime cache keyonnxruntime— update Eigen hash patch for v1.21.1 deps.txt formatonnxruntime— re-clone if Eigen patch not appliedonnxruntime— clean CMake cache when applying Eigen hash patchonnxruntime— apply Eigen hash patch unconditionally- strip placeholder suffix from socketbin versions
publish— read base version from current package being generatedonnxruntime— patch Eigen hash to match GitLab archive formatonnxruntime— disable TLS verification for CMake downloadsonnxruntime— update to v1.21.1 to fix Eigen hash mismatch- remove yoga-layout patch reference from root package.json
cli— handle missing yoga-layout WASM files gracefullybootstrap— avoid logger initialization before stdout is readycli— correct ESLint config paths to monorepo rootbuild— read socketbin spec from actual package.jsoncompress— align cache key generation with socket-libscan— resolve TypeScript errors from merged PRslint— exclude test fixtures from Biome lintinggit— correct import path for paths modulebootstrap— load Intl polyfill before logger to prevent smol build failuretest— delete obsolete bootstrap test and fix provider factory assertionstest— add missing paths mock for provider factory teststest— fix constructor mocks and add missing canSelfUpdate exporttest— replace runCommandQuiet with spawn and fix mock constructorstypes— resolve TypeScript errors in GitLab providercli-with-sentry— write esbuild output and add gitignoresmol— fix MODULE_NOT_FOUND error for socketsecurity bootstrapci— disable pip cache in build-wasm to prevent cache failuresci— correct artifact paths in build-sea workflowci— correct artifact paths in build-smol workflowcli— suppress esbuild warnings in CLI buildci— correct socket package verification in build-sea workflowci— remove CLI build from build-deps job in SEA workflowci— add detailed cache diagnostics to build-sea workflowai— update onnxruntime to 1.21.0+ for INT4 quantization supportci— add WASM asset verification before CLI build in SEA workflowci— include bootstrap deps in SEA binary cache keyci— include bootstrap deps in smol binary cache keysmol— add diagnostic logging for bootstrap file locationci— correct artifact download path and add relocation logicci— add verification step for downloaded build artifactssmol— fail build if bootstrap cannot be copiedlint— remove unused variables and parametersscripts— replace undefined runCommandQuiet with spawnsocket-fix— add missing import and fix optional prNumber typesocket-fix— add remote branch cleanup on PR creation failuresmol— optimize build flow and fix macOS ARM64 signingci— split dependency builds from matrix parallelizationsea— use versionSemver from node-version.json to avoid double 'v' prefixsea— decompress cli.js.bz instead of using build/ intermediatesea— auto-build CLI package when missingci— build bootstrap package before socket and smol/sea builderssocket— reference bootstrap files from packages/bootstrape2e— check JS binary existence before running testse2e— error and exit if binary doesn't exist when explicitly requestede2e— disable Node.js binary forwarding in .env.testcli— remove unnecessary force: true from safeDeleteSync callsbootstrap— export .config/node-version.mjs for workspace importscli— auto-enable RUN_E2E_TESTS when running e2e.mjssocket— handle prefix-only modules in smol transformsocket— correct internal module paths in smol transformci— skip cache restore when force rebuild is requestednode-smol-builder— use socket package bootstrap not local stubnode-smol-builder— add placeholder bootstrap for socketsecurity patchsea-builder— add shell execution for postject on Windowssea-builder— use direct postject path instead of pnpm execsea-builder— add postject as catalog devDependencyci— enable cross-OS cache sharing for Windows buildsci— pass --force flag to WASM build scripts when force rebuild requestedci— move Windows WASM cache check before build attemptci— require WASM cache for Windows SEA buildsci— add wasm-opt to PATH for Windows Emscripten buildssea— strip leading '--' from pnpm arguments for correct parsingsea— enable cross-platform SEA builds using prebuilt Node binariesci— limit SEA builds to native architectures onlyci— correct SEA binary build for cross-platform compilationbuild— resolve SEA build failures across platformspackages— correct spawn result access in package build scriptsbuild— correct spawn result access in build orchestration scriptswasm— correct spawn result property access in WASM build scriptsscripts— resolve duplicate spawn import and incorrect result accessci— remove pip upgrade to improve Python dependency caching- move .node-source to packages/node-smol-builder/build/
onnx— output to dist/ directory instead of build/wasm/ci— save ONNX build cache even on failureonnx— fix second readCheckpoint usage in export stageonnx— use correct checkpoint function namebuild— enable WASM features in wasm-opt optimizationonnx— locate WASM files in MinSizeRel subdirectorysmol— use compressed binary in Final distribution directorybuild— use fs.statfs for reliable cross-platform disk space checkci— use requirements.txt for proper pip cachingonnx— upgrade to v1.23.2 to resolve Eigen hash mismatchwasm— correct checkDiskSpace parameter units (GB not bytes)onnx— use build.sh script instead of direct CMakewasm— use explicit EMSDK paths for wasm-opt and wasm-striponnx-runtime— remove existing source dir before clone and add debug loggingwasm— use shell:true for wasm-opt/wasm-strip to inherit emsdk PATHsocketbin-cli-ai— auto-clean stale checkpoints when artifacts missingonnx-runtime— auto-clean stale checkpoints and use existsSyncyoga-layout— auto-clean stale checkpoints when artifacts missingyoga-layout— throw errors instead of warnings on missing artifactsci— add debugging output for WASM build artifact verificationbuild-infra— replace exec wrappers with direct spawn callsai— add progress indicator for brotli compressionbuild-infra— add exec wrapper to builder classesci— fail builds when WASM artifacts are missingai— define originalSize/quantSize before useci— add cache artifact verification to WASM buildsonnx— use proper spawn command/args pattern- replace build-exec with spawn in remaining builder packages
onnx— replace build-exec with spawnci— replace shasum with sha256sum for Windows compatibilityci— use standard ubuntu-latest runners for WASM buildsnode-smol— use console.log instead of logger.log in binary smoke testcli-ai— make INT4 quantization optional with graceful fallbackci— correct INT4 quantization import and remove invalid autocrlfci— remove push triggers from build-wasm to avoid runner contentioncli-ai— correct import path for matmul_4bits_quantizerci— require onnxruntime>=1.20.0 for INT4 quantizationci— use optimum[onnx] instead of optimum[exporters]build-infra— use result.code instead of result.statusbuild-infra— import printSubstep for debug loggingbuild-infra— use shell for Python detection on all platformsbuild-infra— try multiple Python command names in version checkbuild-infra— handle undefined status in Python checkbuild-infra— fix spawn calls to use proper command+args patternbuild-infra— restore shell: WIN32 option in Python checkbuild-infra— use direct python3 execution without shellbuild-infra— add detailed error logging to Python checkci— add Python verification step for debuggingci— setup Python for all platforms in smol buildci— add Python 3.11 setup for WASM builds in SEA jobbuild-infra— remove duplicate imports in tool-installernode-smol-builder— replace build-exec with spawn wrappersci— add WASM asset restoration to SEA build jobci— correct package names and cache key generationci— ensure dist directories exist before verificationci— include node-smol-builder patches and additions in cache keysci— update patches directory path from build/patches to patchesci— update actions/cache to v4.3.0ci— add workflow_call trigger to build-wasm workflowci— add WASM asset preparation before CI testscli— remove unused imports in optional-models.mtse2e— prompt for sea and smol binaries separatelytest— update tests for read-only ENV properties from @socketsecurity/libtest— skip Unix permission checks on Windowsenv— convert CI to boolean and fix type comparisone2e— correct property names and assertions in critical commands testtests— correct import paths in E2E dlx testtest— correct e2e test exclusion patternpaths— replace path.sep with normalizePath across codebase- use forward-slash patterns for normalized path matching
- normalize paths consistently across platforms
shadow/npm— wrap path.join calls with normalizePathtests— resolve cross-platform npm and path issuescli— resolve TypeScript error in shadowNpmBase cwd handlingcli— pass converted cwd to spawn in shadowNpmBase- improve developer onboarding and fix broken commands
cli— use platform-specific PATH separator in npm tests- remove accidental gitlinks for yoga source directories
cli— make path tests cross-platform compatiblebuild— use fileURLToPath for cross-platform path comparison in esbuildci— prevent diagnostic checks from stopping script executiongitignore— restore dist/ ignore and update build artifact documentationtest— use tmpdir for patch discover test to avoid spawn failuresci— remove del-cli from test-setup-scriptci— remove redundant pnpm install from test-setup-scriptci— replace rm -rf with cross-platform del-cli commandcli— normalize paths for Windows compatibility in completion and tildifycli— update NODE_VERSION to getNodeVersion()cli— skip update checks in test environmentstests— update test imports and fix NpmConfig mockutils— update remaining ecosystem.mjs imports to types.mjscli— update ONNX runtime extractionbuild-infra— improve Emscripten and build executionscripts— add missing colors import in verify-node-builddeps— use socket-lib 1.3.5 with Windows Proxy fixtests— pass undefined env to avoid multiple process.env spreadstests— revert to working spawn pattern from commit 39ee9465tests— use Proxy in test mode to preserve Windows env behaviortests— use exact spawn env pattern from working commit 39ee9465tests— omit env option when no custom env vars providedtests— avoid spreading process.env in spawn callstests— preserve process.env proxy for Windowsci— resolve dependency caching issue causing test failurescli— resolve TypeScript strict mode errorsci— use consistent pnpm --filter pattern in test setupci— use pnpm --filter to run scripts in monorepo contextci— remove redundant cd commands in workflow scriptsdeps— correct @socketsecurity/lib references in workspace packagesscan— add optional chaining for spinner safetypatch— wrap logger output in outputKind checks for JSON/markdownpatch— use optional chaining for spinner to handle null in teststests— update CI handle test imports and debug APItests— update debug imports and skip path-resolve testtests— add missing stdout/stderr destructuring in optimize testscli— disable interactive help menu in test environmentstests— replace await import with vi.importMock in fetch-threat-feed teststests— replace helper functions with direct mocks in fetch-list-repos and fetch-list-all-repostests— replace await import with vi.importMock in remaining repository teststests— use vi.importMock() consistently in fetch-update-repo teststests— rewrite fetch-delete-repo tests to match actual implementationtests— use vi.importMock() consistently in fetch-create-repo testsdlx— skip cache entries with invalid metadata in listDlxCachetests— correct UNKNOWN_ERROR import in errors.test.mtstests— add missing await to async operations in optimize testsci— clear Vitest cache before running teststest— correct mock setup for scan teststest— correct mock setup for repository output teststest— correct mock setup for output-security-policy teststest— correct mock setup for output-quota teststest— correct mock setup for output-license-policy teststest— correct mock setup for output-dependencies teststests— correct import paths and logger references in organization teststests— remove invalid await from destructuring in scan testsconfig— handle Buffer return from safeReadFileSync in findSocketYmlSynctests— update API requirements output test expectationstests— resolve shadow/links PATH and Windows test issuestests— correct socket/alerts mock pathstests— correct pnpm scanning test mockstests— fix environment variable mocking in API teststests— update API error message expectationstests— update CLI behavior expectations for interactive menutests— correct org-slug test mocks and expectationstests— update socket.json test expectationstest— resolve mock configuration issues in validation and helper teststests— update SDK API mock expectations for v3.0.6cli— add ask, console, and patch commands to validation listtests— add missing color functions to yoctocolors-cjs mocktests— correct module import paths in shadow links and performance teststests— correct module file name importstests— correct remaining import paths in test filestests— remove getProcessEnv import that doesn't existtests— correct module mock paths in test helperstests— correct additional import paths in utils subdirectoriestests— correct import paths and remove orphaned test fileswindows— add LOCALAPPDATA fallback for app data pathtest— resolve binCliPath undefined errors and CI shimmer testtest— correct import paths in 76 command test filestest— correct import path in constants.test.mtstest— resolve SDK dynamic require error in vitest configbuild— use getLocalPackageAliases instead of hardcoded pathstest— enable test isolation to prevent worker thread termination errorstest— correct output-threat-feed mock path for serializeResultJsontest— correct arborist-helpers mock path for idToNpmPurltest— correct handle-create-new-scan mocks and expectationstests— properly mock paths and dependencies in postinstall-wrapper teststests— properly mock @socketsecurity/lib/debug in debug tests- resolve socket-lib bundled external dependencies in esbuild
- add missing TypeScript base config at root
- remove @socketsecurity/lib link override for CI build compatibility
- update @socketbin/cli packages to available version 0.0.0
- replace fragile regex parsing with file-based JSON extraction in coana discovery
- resolve pre-existing unit test failures
ci— remove coverage-script and coverage-report-scriptci— update workflow SHAs to d8ff3b05- update build scripts to use pnpm filter for monorepo
- link to local @socketsecurity/sdk for development Replace @socketsecurity/sdk version dependency with link to sibling socket-sdk-js directory. Remove SDK patch as types are now fixed at source. This enables development on SDK and CLI simultaneously and ensures we're testing against the latest SDK changes.
- patch @socketsecurity/sdk@2.0.1 to correct type definition paths The SDK package.json incorrectly references index.d.mts and testing.d.mts but the actual files are index.d.ts and testing.d.ts. This patch corrects the types field to point to the correct .d.ts files. Note: This fixes the "could not find declaration file" errors, but there are still type export issues with SDK v2.0.1 that need to be addressed. Socket CLI uses SocketSdkSuccessResult and other types that are not being properly exported from the SDK index despite being defined in types.d.ts.
- suppress lint warning for intentional control character regex Add biome-ignore comment to asciiUnsafeRegexp which intentionally matches control characters for test output cleanup. This is a false positive from the noControlCharactersInRegex rule.
- suppress lint warning for intentional control character regex Add biome-ignore comment to asciiUnsafeRegexp which intentionally matches control characters for test output cleanup. This is a false positive from the noControlCharactersInRegex rule.
- resolve merge conflict in provenance.yml workflow Remove merge conflict markers and use correct publish command that changes to dist directory before publishing @socketsecurity/cli-with-sentry. This ensures the package is published from the correct location.
- handle directory targets according to specification When a directory path is provided, it now recursively scans that directory for all files by appending /*/ to the path pattern. This ensures directory targets work as expected in scanning operations. Also fixes a type annotation issue in getWorkspaceGlobs. Cherry-picked from PR #794 (commit 5f78dfdf) Original author: Martin Torp martin@socket.dev Co-Authored-By: Martin Torp martin@socket.dev
- disable Biome assist to prevent import organization conflicts
- update Biome and ESLint configs for bracket notation support Update linting configuration to support TypeScript bracket notation for index signature properties: - Disable Biome rules: useLiteralKeys, noParameterAssign, noNonNullAssertion, noExplicitAny, noAsyncPromiseExecutor, noAssignInExpressions, useIterableCallbackReturn, noBannedTypes - Disable ESLint rules: no-unexpected-multiline, sort-imports - Apply Biome formatting across codebase This aligns with socket-sdk-js and enables TypeScript TS4111 compliance.
- inject build metadata in esbuild config After migrating from Rollup to esbuild, build metadata values (INLINED_SOCKET_CLI_VERSION, etc.) were no longer being injected, causing the CLI version to display as "vundefined" in the header. Changes: - Added build-time injection of all metadata values via esbuild's define option (version, version hash, dependency versions, build flags) - Implemented proper version hash computation matching Rollup's logic: "${version}:${gitHash}:${randomUUID}${devSuffix}" - Fixed dependency version lookups to use devDependencies (coana, cdxgen, synp) - Renamed esbuild-inject-import-meta.js to .mjs for proper module resolution - Added default export to scripts/constants.mjs for compatibility - Fixed import order in esbuild.cli.config.mjs - Added biome-ignore comments for ANSI escape code patterns in demo The CLI header now correctly shows the version (e.g., "v1.1.25") and all build constants are properly inlined during bundling.
- improve ask command intent parsing and model loading Cache semantic model loading failures to avoid repeated error messages. Previously tried to load the model 6 times per query, now fails once and caches. Improve package name extraction to reject common command words like 'vulnerabilities', 'security', 'issues'. Only extracts valid package names like 'express', '@scope/package', etc. Fix esbuild import.meta.url injection by using ESM export syntax instead of CommonJS module.exports format.
- link to local socket-registry for development Update package.json to use local socket-registry for development to access latest exports and constants not yet published to npm. Add scripts/constants.mjs barrel file to re-export all constants modules. Fix lint issues: - Add eslint-disable for intentional process.exit() in SIGINT handler - Add eslint-disable for intentional await in loop for sequential URL checking
- patch https-proxy-agent to prevent Rollup template literal corruption Replace \r\n literals with hex codes (\x0d\x0a) to prevent Rollup from corrupting template literals during bundling process.
- skip processing of large base64-encoded WASM/model files Adds custom Rollup plugin to load external/ files raw without parsing. This fixes build hangs caused by Babel/CommonJS trying to parse 40MB+ base64-encoded strings in onnx-sync.mjs and minilm-sync.mjs. Changes: - Add skip-external-assets plugin to load() files raw - Exclude external/from babel processing - Exclude external/ from commonjs processing
- suppress TypeScript errors for local registry imports Add ambient module declarations for @socketsecurity/registry subpaths. This suppresses TS2307 errors during development when using local builds. The Node.js loader resolves these imports correctly at runtime, and build tools use getLocalPackageAliases() for resolution. Update .gitignore to allow src/types/*/.d.ts (ambient declarations).
- restore ink patch with proper git hashes Regenerate ink@6.3.1.patch using pnpm patch workflow to fix integrity check failures.
- ensure fix script forwards --all, --changed, and --staged flags to lint Updates scripts/fix.mjs to properly forward file filtering flags to the underlying lint command. This ensures consistent behavior across socket-cli, socket-packageurl, and socket-sdk-js repositories. - Add --all, --changed, and --staged options to parseArgs - Build lint command arguments conditionally based on flags - Forward flags to pnpm run lint --fix command - Update script documentation with new options
- resolve all ESLint errors and warnings - Fix undefined NODE_DIR by defining it properly in build-yao-pkg-node.mjs - Add eslint-disable comments for intentional unused variables in catch blocks - Add eslint-disable comments for intentional process.exit() calls in SEA wrapper - Add eslint-disable comments for intentional await-in-loop in retry/batch operations - Auto-fix all import ordering warnings across codebase - Ensure proper import grouping: builtin -> external -> internal -> local
- handle deleted files in lint and test scripts - Add existsSync checks to filter out deleted files before linting - Add existsSync checks in affected-test-mapper to skip deleted test files - Prevents 'No files matching pattern' errors when files are deleted This fixes an issue where git reports deleted files in changed/staged lists, but the files no longer exist on disk, causing lint and test runners to fail.
- improve Ctrl+O output display behavior When Ctrl+O is pressed to show output: - Remove "--- Showing output ---" header for cleaner display - Don't clear the buffer after dumping it - Keep output streaming live to stdout while visible - Allow toggling back to spinner mode This provides a smoother interactive experience where pressing Ctrl+O clears the spinner and shows all output, continuing to stream live until toggled back.
- prevent ENAMETOOLONG in path-resolve tests from circular symlinks The test was using mock-fs.load() to load the entire node_modules tree, which followed circular symlinks between @socketregistry/packageurl-js and @socketsecurity/registry infinitely, causing ENAMETOOLONG errors. Additionally, the registry's dist/external/streaming-iterables.js was not accessible in the mock filesystem because Node's require follows the symlink to the actual socket-registry/registry location. Solution: - Don't load the entire node_modules tree (avoids ENAMETOOLONG) - Load only the registry dist from its actual location since require follows symlinks to socket-registry/registry All 21 path-resolve tests now pass.
- correct SDK API calls and TypeScript types - Fix createOrgFullScan call: use options object with pathsRelativeTo and queryParams - Fix streamOrgFullScan call: use options object with output property - Fix purl-to-ghsa: only include affects when truthy to satisfy exactOptionalPropertyTypes - Fix purl types: replace non-existent PurlQualifiers with Record<string, string>
- correct yoctocolors mock in failMsgWithBadge test Move vi.mock() before imports and use plain functions instead of vi.fn() to properly mock the color functions. Remove spy assertion tests that are no longer applicable with plain function mocks.
- add worker termination error handler to test runner Add unhandledRejection handler to filter out non-fatal vitest worker thread cleanup errors. Prevents false negative test failures. Matches socket-sdk-js implementation for consistent behavior.
- use correct TypeScript check script name Change check:types to check:tsc to match the actual script name in package.json.
- use test.mjs script and suppress worker termination warnings - Update package.json test script to use test.mjs for --all flag support - Add --unhandled-rejections=warn to NODE_OPTIONS to suppress non-fatal unhandled rejection warnings from vitest worker thread cleanup This aligns socket-cli with the test infrastructure used in other socket-* repos and prevents false test failures from worker cleanup.
- handle vitest worker termination errors gracefully Update test runner to capture output and detect worker termination errors. Override exit code to 0 when only worker termination errors occur without actual test failures. This prevents false negatives from known non-fatal vitest cleanup issues.
- suppress TypeScript spread type errors with ts-expect-error Add @ts-expect-error comments to suppress TS2698 errors on getOwn spread operations. While spreading undefined technically works at runtime in modern JavaScript, TypeScript's strict mode rejects it. Since the linter strips out nullish coalescing operators, we use ts-expect-error instead. Files updated: - src/commands/optimize/agent-installer.mts - src/shadow/npm/arborist-helpers.mts - src/shadow/npm/install.mts - src/utils/dlx.mts - src/utils/meow-with-subcommands.mts - src/utils/socket-package-alert.mts
- replace log.progress with log.step in build script - Use log.step() instead of log.progress() to avoid spinner interference - Remove manual line clearing code (no longer needed) - Replace log.failed() with log.error() for consistency - Prevents output interference with dividers and status updates
- resolve TypeScript TS2698 spread type errors with exactOptionalPropertyTypes Add nullish coalescing to getOwn() calls to ensure spread operations always receive objects when exactOptionalPropertyTypes is enabled.
- continue resolving TypeScript errors - Fixed EditablePackageJson import to use ReturnType pattern - Fixed Buffer/NonSharedBuffer .trim() issues in update-store.mts - Fixed ChildProcessType exit event parameter types - Fixed debug namespace calls (isDebugNs, debugFnNs) in error-display.mts Reduced errors from 255 to 251
- resolve TypeScript API migration errors - Convert 2-argument debug calls to namespace variants (debugFnNs) - Replace logger.debug with logger.log (API removed in registry) - Update pluralize calls to use { count } option object - Add missing LATEST and PACKAGE_LOCK_JSON exports - Import namespace debug functions in debug utilities Reduced TypeScript errors from 432 to 255
- update @socketbin workflow for trusted publisher - Remove automatic release trigger (manual dispatch only) - Remove all NODE_AUTH_TOKEN/NPM_TOKEN references - Use OIDC authentication via id-token permission instead - Simplify version determination (no release event handling) Trusted publisher uses GitHub OIDC tokens, no npm token needed.
- add file extension filtering to affected test mapper - Skip non-code files (images, docs, etc.) in test mapping - Prevents running all tests for non-code file changes - Improves test performance
- resolve ESLint and TypeScript linting issues Fix inline comment positioning (line-comment-position): - Move inline comments to separate lines above code - Affected: cache-strategies.mts and all test files Fix TypeScript index signature access: - Change dot notation to bracket notation for metadata properties - Affected: performance.test.mts Add ESLint disable comments: - Disable no-control-regex for ANSI color code tests - Affected: output-formatting-tables.test.mts All files now pass
pnpm run checksuccessfully. - use Object.create(null) for ResultErrorOptions Replace proto: null in typed object literal with Object.create(null) Follows CLAUDE.md pattern for empty null-prototype objects
ci— update socket-registry SHA to 5b2880d7ci— update socket-registry SHA to 662bbcabci— update socket-registry SHA to b94a1086ci— update socket-registry SHA to dba06046ci— update socket-registry SHA to 0782233cci— correct socket-registry SHA to full hashci— update socket-registry SHA to 43a668e1ci— update socket-registry SHA to d1bbbbadci— update socket-registry SHA to dc181fb5ci— update socket-registry SHA to 08fba31aci— update socket-registry workflows to latest SHA (c61feb5e)ci— pin socket-registry workflows to SHA instead of @main- improve organization capabilities detection for plan variants
- enterprise plan filter (#785) Signed-off-by: Ahmad Nassri email@ahmadnassri.com Co-authored-by: John-David Dalton jdalton@users.noreply.github.com
- handle pnpm frozen-lockfile in CI for optimize command In CI environments, pnpm automatically runs with --frozen-lockfile which prevents lockfile updates. When the optimize command tries to add overrides and update the lockfile, it fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Added explicit --no-frozen-lockfile flag when running pnpm install in CI mode to allow the lockfile to be updated with Socket.dev overrides.
- Add fallback for npm exec path detection When constants.npmExecPath from the published registry doesn't exist or isn't executable, fall back to using whichBin to find npm. This fixes CI failures where the published version's npm-exec-path module might not correctly detect npm in certain environments.
- Add defensive check for whichBinSync return value The published version of @socketsecurity/registry may return a string when only one result is found even with all: true. This defensive check handles both cases to ensure compatibility with the current published version and future versions that properly return an array.
socket organization quotais no longer hidden and now shows remaining quota, total quota, usage percentage, and the next refresh time in text and markdown output.
- Advanced TUI components and styling for rich terminal interfaces:
- MixedText component: Render text with multiple styled sections, perfect for syntax highlighting and rich formatting
- Fragment component: Group elements without layout impact, enabling cleaner component composition
- Extended border styles: double-left-right, double-top-bottom, and classic ASCII borders
- Custom border characters: Full control over border rendering with custom character sets
- ANSI 256-color support: Use extended color palette with
ansi:123or bare number notation for vibrant terminal output
- Comprehensive TUI styling and layout properties for terminal interfaces:
- Text styling: weight (normal, bold, light), dimColor for faded appearance, strikethrough decoration
- Text layout: align (left, center, right), wrap (wrap, nowrap) for content control
- Flex layout: flexBasis for initial sizing, flexWrap for multi-line layouts, alignContent for line distribution
- Advanced positioning: display (flex, none), position (relative, absolute) with inset controls (top, right, bottom, left)
- Dimension constraints: minWidth, maxWidth, minHeight, maxHeight for responsive layouts
- Overflow control: overflow, overflowX, overflowY for content that exceeds container bounds
- Border customization: borderEdges for selective border rendering (top, right, bottom, left)
- Layout spacing: rowGap and columnGap for fine-grained flex item spacing
- Updated to @socketsecurity/socket-patch@1.2.0.
- Updated Coana CLI to v14.12.148.
socket scan createnow accepts--make-default-branch(mirrors themake_default_branchAPI field) instead of--default-branch. The old name keeps working but emits a deprecation warning.
socket scan create --default-branch/--defaultBranch— use--make-default-branchinstead. The legacy names still work during the deprecation window but emit a warning.
- Prevent heap overflow in large monorepo scans by using streaming-based filtering to avoid accumulating all file paths in memory before filtering.
socket scan createnow rejects--default-branch=<name>and--default-branch <name>(space-separated) with an actionable error instead of silently dropping the branch name. Scans that used the misuse shape were getting recorded without a branch tag and disappearing from the Main/PR dashboard tabs.socket repository create/socket repository updatenow reject bare--default-branch(no value) and--default-branch=(empty value). Previously both persisted a blank default-branch name on the repo record.socket cdxgenno longer silently produces SBOMs with an emptycomponentsarray when run in the default--lifecycle pre-build+--no-install-depsmode against a Node.js project that has no lockfile and nonode_modules/. The command now fails fast with an actionable error (install dependencies or pass--lifecycle build), and when the generated BOM still ends up empty for any other reason (e.g. overly narrow--filter/--only), emits a post-run warning so the condition is surfaced instead of shipping an SBOM that renders as "no alerts" on the Socket dashboard.
2.1.0 - 2025-11-02
- Unified DLX manifest storage for packages and binary downloads with persistent caching and TTL support
- Progressive enhancement with ONNX Runtime stub for optional NLP features
- SHA-256 checksum verification for Python build standalone downloads
- Optional external alias detection for TypeScript configurations
--reach-use-unreachable-from-precomputationflag forscan reachandscan createcommands to use precomputed unreachable information for improved reachability analysis accuracy
- DLX manifest now uses unified format supporting both npm packages and binary downloads
- Standardized environment variable naming with SOCKETCLI prefix
- Preflight downloads now stagger with variable delays (1-3 seconds) to avoid resource contention
- Bootstrap stream/promises module path corrected for smol builds
- Bootstrap error handling improved for clearer failure messages
- Windows path handling now correctly processes UNC paths
2.0.10 - 2025-10-31
- Tab completion script now resolves CLI package root correctly
- SDK scan options flattened and repo parameter made conditional
- Output handling now safely checks for null before calling toString()
- Environment variable fallbacks from v1.x restored for backward compatibility
- Directory creation EEXIST errors now handled gracefully
2.0.9 - 2025-10-31
- Updated @socketsecurity/lib to v2.10.2 with critical DLX fixes for scoped package parsing
2.0.8 - 2025-10-31
- Binary name resolution for external tools (@coana-tech/cli, @cyclonedx/cdxgen, synp) in dlx execution
- Preflight downloads now correctly specify binary names for background package caching
2.0.7 - 2025-10-31
- Shimmer effect to bootstrap spinner for enhanced visual feedback during CLI download
- Consolidated SOCKET_CLI_ISSUES_URL constant to socket constants module for better organization
2.0.6 - 2025-10-31
- Shadow npm spawn mechanism now properly uses spawnNode abstraction for SEA binary compatibility
- IPC handshake structure for shadow npm processes with correct parent_pid and subprocess fields
2.0.2 - 2025-10-30
- Fixed import from @socketsecurity/registry to @socketsecurity/lib
2.0.1 - 2025-10-30
- Updated @socketsecurity/lib to v2.9.0 with Socket.dev URL constants and enhanced error messages
- Updated @socketsecurity/sdk to v3.0.21
- Normalized lock behavior across codebase
- Bootstrap path resolution in binary builders to correct path
2.0.0 - 2025-10-29
- BREAKING: CLI now ships as single executable binary requiring no external Node.js installation
- GitLab merge request support for
socket fix - Persistent GHSA tracking to avoid duplicate fixes
- Markdown output support for
socket fixandsocket optimize --reach-min-severityflag to filter reachability analysis by vulnerability severity threshold
- Target directory handling in reachability analysis for scan commands
1.1.25 - 2025-10-10
--no-major-updatesflag--show-affected-direct-dependenciesflag
- Provenance handling
1.1.24 - 2025-10-10
--minimum-release-ageflag forsocket fix- SOCKET_CLI_COANA_LOCAL_PATH environment variable
- Organization capabilities detection
- Enterprise plan filtering
1.1.23 - 2025-09-22
- Renamed
--dont-apply-fixesto--no-apply-fixes(old flag remains as alias) - pnpm dlx operations no longer use
--ignore-scripts
- Error handling in optimize command for pnpm
1.1.22 - 2025-09-20
- Renamed
--only-computeto--dont-apply-fixesforsocket fix(old flag remains as alias)
- Interactive prompts in
socket optimizewith pnpm - Git repository name sanitization
1.1.21 - 2025-09-20
--compact-headerflag
- Error handling in
socket optimize
1.1.20 - 2025-09-19
- Terminal link support
- Windows package manager execution
1.1.13 - 2025-09-16
--output-fileflag forsocket fix--only-computeflag forsocket fix
1.1.9 - 2025-09-11
socket fix --idnow accepts CVE IDs and PURLs
- SOCKET_CLI_API_TIMEOUT environment variable lookup
1.1.7 - 2025-09-11
--no-spinnerflag
- Proxy support
1.1.4 - 2025-09-09
--report-levelflag for scan output control
1.1.1 - 2025-09-04
- Legacy
--testand--test-scriptflags fromsocket fix
1.1.0 - 2025-09-03
- Package versions in
socket npmsecurity reports
1.0.111 - 2025-09-03
--range-styleflag forsocket fix
1.0.106 - 2025-09-02
--reach-skip-cacheflag
1.0.89 - 2025-08-15
socket scan create --reachfor manifest scanning
1.0.85 - 2025-08-01
- SOCKET_CLI_NPM_PATH environment variable
1.0.82 - 2025-07-30
--max-old-space-sizeand--max-semi-space-sizeflags
1.0.73 - 2025-07-14
- Automatic
.socket.facts.jsondetection
1.0.69 - 2025-07-10
--no-pr-checkflag forsocket fix
1.0.0 - 2025-06-13
- Official v1.0.0 release
- Added
socket org depsalias command
- Moved dependencies command to a subcommand of organization
- Improved UX for threat-feed and audit-logs
- Removed Node 18 deprecation warnings
- Removed v1 preparation flags
0.15.64 - 2025-06-13
- Improved
socket fixerror handling when server rejects request
- Final pre-v1.0.0 stability improvements
0.15.63 - 2025-06-12
- Enhanced debugging capabilities
0.15.62 - 2025-06-12
- Avoided double installing during
socket fixoperations
0.15.61 - 2025-06-11
- Memory management for
socket fixwith packument cache clearing
0.15.60 - 2025-06-10
- Widened Node.js test matrix
- Removed Node 18 support due to native-ts compatibility
0.15.59 - 2025-06-09
- Reduced Node version restrictions on CLI
0.15.57 - 2025-06-06
- Added
socket threat-feedsearch flags
0.15.56 - 2025-05-07
socket manifest setupfor project configuration- Enhanced debugging output and error handling
0.15.0 - 2025-05-07
- Enhanced
socket threat-feedwith new API endpoints socket.jsonconfiguration support- Improved
socket fixerror handling
- Avoid double installing with
socket fix - CI/CD improvements reducing GitHub Action dependencies for
socket fix
0.14.155 - 2025-05-07
SOCKET_CLI_API_BASE_URLfor base URL configurationDISABLE_GITHUB_CACHEenvironment variablecdxgenlifecycle logging and documentation hyperlinks
- Set
exitCode=1when login steps fail - Fixed Socket package URLs
- Band-aid fix for
socket analytics - Improved handling of non-SDK API calls
- Enhanced JSON-safe API handling
- Updated
cdxgenflags and configuration
0.14.0 - 2024-10-10
socket optimizeto apply Socket registry overrides- Suggestion flows to
socket scan create - JSON/markdown output support for
socket repos list - Enhanced organization command with
--jsonand--markdownflags SOCKET_CLI_NO_API_TOKENenvironment variable support- Improved test snapshot updating
- Spinner management in report flow and after API errors
- API error handling for non-SDK calls
- Package URL corrections
- Added Node permissions for shadow-bin
0.13.0 - 2024-09-06
socket threat-feedfor security threat information
0.12.0 - 2024-08-30
- Diff Scan command for comparing scan results
- Analytics enhancements and data visualization
- Feature to save analytics data to local files
0.11.0 - 2024-08-05
- Organization listing capability
0.10.0 - 2024-07-17
- Analytics command with graphical data visualization
- Interactive charts and graphs
0.9.0 - 2023-12-01
- Automatic latest version fetching for
socket info - Package scoring integration
- Human-readable issue rendering with clickable links
- Enhanced package analysis with scores
- Smart defaults for package version resolution
- Improved issue visualization and reporting
0.8.0 - 2023-08-10
- Configuration-based warnings from settings
- Enhanced
socket npminstallation safety checks
- Dropped Node 14 support (EOL April 2023)
- Added Node 16 manual testing due to c8 segfault issues
0.7.1 - 2023-06-13
- Python report creation capabilities
- CLI login/logout functionality
- Lockfile handling to ensure saves on
socket npm install - Report creation issues
- Python uploads via CLI
- Switched to base64 encoding for certain operations
0.6.0 - 2023-04-11
- Enhanced update notifier for npm wrapper
- TTY IPC to mitigate sub-shell prompts
0.5.0 - 2023-03-16
- npm/npx wrapper commands (
socket npm,socket npx) - npm provenance and publish action support
- Reusable consistent flags across commands
0.4.0 - 2023-01-20
- Persistent authentication - CLI remembers API key for full duration
- Comprehensive TypeScript integration and type checks
- Enhanced development tooling and dependencies
0.3.0 - 2022-12-13
- Support for globbed input and ignores for package scanning
--strictand--allflags to commands- Configuration support using
@socketsecurity/config
- Improved error handling and messaging
- Stricter TypeScript configuration
- Improved tests
0.2.1 - 2022-11-23
- Update notifier to inform users of new CLI versions
0.2.0 - 2022-11-23
- New
socket report viewfor viewing existing reports --viewflag toreport createfor immediate viewing- Enhanced report creation and viewing capabilities
- Synced up report create command with report view functionality
- Synced up info command with report view
- Improved examples in
--helpoutput
- Updated documentation and README with new features
0.1.2 - 2022-11-17
- Node 19 testing support
- Improved documentation
0.1.1 - 2022-11-07
- Extended README documentation
- Removed accidental debug code
0.1.0 - 2022-11-07
- Initial Socket CLI release
socket infofor package security informationsocket report createfor generating security reports- Basic CLI infrastructure and configuration