Wave 38: complete release readiness - #399
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
ty-everett
left a comment
There was a problem hiding this comment.
Exact-head maintainer review completed for 33656c3. I verified the dependency dispositions and 24-hour maturity floor, all 19 override-removal rehearsals, additive package-export fixes, public API/wire/storage/error/default and CORS/CSP compatibility, the restored fail-closed 90% repository patch-coverage gate, browser/mobile artifact contracts, and removal of unsupported Actions resource/cache instrumentation. Hosted evidence is clean: 58 checks passed, one scope-appropriate non-coverage job skipped, zero failures; CodeQL passed; the repository-owned Sonar gate and Sonar API report zero new issues and zero hotspots; Codecov reports all modified coverable lines covered. There are no unresolved review threads. Socket’s sole warning is its known obfuscated-code heuristic on the official webpack@5.109.2 bundle; the registry artifact is integrity-pinned and Socket’s PR gate, dependency review, audit, and CodeQL all pass. No package, image, tag, release, or deployment is authorized by this merge. GitHub does not permit an author to approve their own PR, so this COMMENT review records the exact-head review and the admin merge will explicitly bypass only the independent-approval requirement.



Summary
Completes the Wave 38 release-readiness program without publishing packages,
images, tags, or releases.
24-hour release-age floor and classifying every remaining delta
prevent a reproduced vulnerable graph or preserve deterministic codegen
standalone service manifests
gate
source map, bin, side-effect declaration, optional dependency, and peer
contract in clean consumers
.tssubpath-pattern shadowing additively, preservingall existing import forms
plus the wallet Metro/Hermes contract
and opaque-origin access by default, with exact allowlist, credentials, and
disabled modes remaining opt-in; CSP configuration stays independent
compatibility/consensus findings stay in owned, dated exceptions
Actions-supported timing evidence and reduces repeated work through the
existing shared build, affected-package selection, pnpm cache, immutable
MongoDB binary cache, and removal of redundant esbuild rebuilds
and repository-health documentation
Closes no release action and performs no publication. Tracker: #324.
Compatibility and security
behavior is preserved
test is introduced
conditions
vulnerabilities
webpack@5.109.2registry artifact is lock-integrity pinned; the heuristic flags bundled
webpack code, while Socket's PR gate, dependency review, audit, and
CodeQL all pass
Dependency evidence
pnpm audit --audit-level=highand all eight standalonenpm audit --audit-level=highchecks report zero vulnerabilities; advanced CodeQL with security-extended queries and the exact-head zero-new-findings gates remain required CI checks.pack:checkcontracts, 13 exact browser consumers, wallet Metro/Hermes, compiled documentation examples against 21 exact tarballs, 30 canonical license tarballs, and all standalone infrastructure install/build/lint/test paths pass locally.Completion evidence
documentation, version consistency, license, and security gates pass