Skip to content

chore(ci): bump socket-registry action SHAs#570

Merged
John-David Dalton (jdalton) merged 2 commits intomainfrom
chore/bump-socket-registry-sha
Apr 8, 2026
Merged

chore(ci): bump socket-registry action SHAs#570
John-David Dalton (jdalton) merged 2 commits intomainfrom
chore/bump-socket-registry-sha

Conversation

@jdalton
Copy link
Copy Markdown
Contributor

Summary

Bump socket-registry action SHAs to the latest main after the full Layer 1-4 cascade (#209, #210, #211, #212).

What changed upstream

  • Native pnpm: pnpm/action-setup replaced with direct binary download (v10.33.0, checksum-verified)
  • Native zizmor: Docker-based zizmor-action replaced with native binary (v1.23.1, checksum-verified)
  • sfw-free checksums: SHA-256 verification on all sfw-free binary downloads
  • sfw shims: All supported ecosystems (npm, yarn, pnpm, pip, uv, cargo) shimmed through the Socket firewall
  • No cache: Removed pnpm cache from setup-node to eliminate cache-poisoning vectors
  • GIT_SSL_NO_VERIFY workaround: Temporary fix until sfw-free sets GIT_SSL_CAINFO

@jdalton John-David Dalton (jdalton) force-pushed the chore/bump-socket-registry-sha branch 4 times, most recently from c74bf37 to a6943a8 Compare April 8, 2026 17:46
@jdalton John-David Dalton (jdalton) merged commit eb7b923 into main Apr 8, 2026
10 checks passed
@jdalton John-David Dalton (jdalton) deleted the chore/bump-socket-registry-sha branch April 8, 2026 20:14
John-David Dalton (jdalton) added a commit that referenced this pull request Apr 8, 2026
* chore(ci): bump socket-registry action SHAs to latest

* chore: align engines to node >=18.20.8 and pnpm >=10.33.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants