Skip to content

chore(ci): cascade socket-registry pin to 3f2f2c00#626

Merged
John-David Dalton (jdalton) merged 2 commits intomainfrom
chore/registry-cascade
Apr 27, 2026
Merged

chore(ci): cascade socket-registry pin to 3f2f2c00#626
John-David Dalton (jdalton) merged 2 commits intomainfrom
chore/registry-cascade

Conversation

@jdalton
Copy link
Copy Markdown
Contributor

Self-landable split from #620.

Bumps SocketDev/socket-registry workflow pins from ea1986b8 to 3f2f2c00. Picks up:

  • bootstrap-from-registry step in install/action.yml (pre-seeds @socketsecurity/lib before pnpm install)
  • path-guard fleet cascade

Test plan

  • CI passes

Picks up the latest socket-registry workflow updates (currently the
bootstrap-from-registry step in install/action.yml + the path-guard
fleet rollout cascade).

Self-landable split from #620.
Picks up the firewall-checker fix in @SocketDev/socket-registry —
any alert from Socket Firewall now blocks the bootstrap (no severity
threshold; the API only returns alerts when a package is flagged
as malware, so any alert means malware).

Cascade chain:
  check-firewall.mts        Layer 1  e4193847
  setup-and-install         Layer 2  b94c9571
  reusable workflows        Layer 3  85a2fc0d  ← propagation SHA
  _local-not-for-reuse-*    Layer 4  25ec2c76  (socket-registry only)
@jdalton
Copy link
Copy Markdown
Contributor Author

bugbot run

@jdalton John-David Dalton (jdalton) merged commit 1b6a618 into main Apr 27, 2026
11 checks passed
@jdalton John-David Dalton (jdalton) deleted the chore/registry-cascade branch April 27, 2026 18:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants