Skip to content

Conversation

@mtorp
Copy link
Contributor

@mtorp mtorp commented Dec 9, 2025

  • Add an e2e test suite that covers a good portion of the socket scan reach options and variants, and all tests the structure of the resulting .socket.facts.json files.
  • Update @coana-tech/cli to version 14.12.118 (changelog here)
    • Adds support for Yarn worktrees
    • Various other minor bug fixes

Note

Adds extensive E2E tests for socket scan reach (multi-ecosystem, cwd/target, output), updates fixtures, refines related tests, and bumps @coana-tech/cli to 14.12.117 with version 1.1.44.

  • Tests:
    • Reachability E2E: New src/commands/scan/cmd-scan-reach.e2e.test.mts covering multi-ecosystem filtering, target/--cwd behavior, excludes, output location, and facts file structure validation.
    • Scan Create: Update paths to use test/fixtures/commands/scan/simple-npm and expand reachability flag validations.
    • Reach (unit-like): Migrate fixtures path and broaden flag handling/error tests in cmd-scan-reach.test.mts.
    • Fix E2E: Improve temp fixture handling and env setup in cmd-fix.e2e.test.mts.
  • Fixtures:
    • Add npm workspace mono project (test/fixtures/commands/scan/npm-test-workspace-mono/**) and Python requirements fixture; minor simple-npm tweaks.
  • Versioning/Deps:
    • Bump package version to 1.1.44; update CHANGELOG.
    • Upgrade devDependency @coana-tech/cli to 14.12.117 (and lockfile entries).
  • Lockfile:
    • Update pnpm-lock.yaml to reflect dependency changes.

Written by Cursor Bugbot for commit 8cae3d1. Configure here.

@socket-security
Copy link

socket-security bot commented Dec 9, 2025

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

Copy link

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment @cursor review or bugbot run to trigger another review on this PR

@socket-security-staging
Copy link

socket-security-staging bot commented Dec 9, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​coana-tech/​cli@​14.12.113 ⏵ 14.12.11889 +110080 +196 +1100

View full report

@socket-security-staging
Copy link

socket-security-staging bot commented Dec 9, 2025

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@mtorp mtorp requested a review from jdalton December 9, 2025 12:44
@jdalton jdalton merged commit 903cc00 into v1.x Dec 9, 2025
7 checks passed
@jdalton jdalton deleted the reachability-e2e-tests branch December 9, 2025 14:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants