Skip to content

chore(ci): bump socket-registry action SHAs#161

Merged
jdalton merged 1 commit intomainfrom
chore/bump-socket-registry-sha
Apr 8, 2026
Merged

chore(ci): bump socket-registry action SHAs#161
jdalton merged 1 commit intomainfrom
chore/bump-socket-registry-sha

Conversation

@jdalton
Copy link
Copy Markdown
Collaborator

@jdalton jdalton commented Apr 8, 2026

Summary

Bump socket-registry action SHAs to the latest main after the full Layer 1-4 cascade (#209, #210, #211, #212).

What changed upstream

  • Native pnpm: pnpm/action-setup replaced with direct binary download (v10.33.0, checksum-verified)
  • Native zizmor: Docker-based zizmor-action replaced with native binary (v1.23.1, checksum-verified)
  • sfw-free checksums: SHA-256 verification on all sfw-free binary downloads
  • sfw shims: All supported ecosystems (npm, yarn, pnpm, pip, uv, cargo) shimmed through the Socket firewall
  • No cache: Removed pnpm cache from setup-node to eliminate cache-poisoning vectors
  • GIT_SSL_NO_VERIFY workaround: Temporary fix until sfw-free sets GIT_SSL_CAINFO

@jdalton jdalton force-pushed the chore/bump-socket-registry-sha branch 2 times, most recently from 6dd3d9c to d3be60b Compare April 8, 2026 17:46
@jdalton jdalton force-pushed the chore/bump-socket-registry-sha branch from d3be60b to 279c3ab Compare April 8, 2026 17:51
@jdalton jdalton enabled auto-merge (squash) April 8, 2026 18:30
@jdalton jdalton disabled auto-merge April 8, 2026 18:44
@jdalton jdalton merged commit 144939a into main Apr 8, 2026
12 checks passed
@jdalton jdalton deleted the chore/bump-socket-registry-sha branch April 8, 2026 18:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant