Skip to content

feat/bun install socket scanner - #134

Open
taraxvoid wants to merge 2 commits into
mainfrom
feat/bun-install-socket-scanner
Open

taraxvoid wants to merge 2 commits into
mainfrom
feat/bun-install-socket-scanner

Conversation

@taraxvoid

Copy link
Copy Markdown
Owner
  • feat(ci): skip the bunfig security scanner in CI by default
  • fix(bun-install): verify the scanner-free bunfig by parsing it, not grep

taraxvoid and others added 2 commits October 6, 2026 09:28
Socket's bun scanner calls a third-party API on every install, so a network
blip or API change can fail an otherwise-green build, and reruns of the same
commit aren't guaranteed to agree. Local installs keep running it.

- actions/bun-install: `bun install --frozen-lockfile` with a `socket-scanner`
  input (default 'false'). When off, installs with a scanner-free copy of
  bunfig.toml via `--config=` (replaces, not merges; other settings still
  apply), leaves a notice, and fails closed on a scanner it can't strip.
- site-ci.yml: same `socket-scanner` input (default false); the bun install
  step inlines the action's script, kept identical by a test. pnpm unchanged.
- ci.yml: voidflow's own unit-test install goes through the action.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The grep check was a heuristic: a package like "foo-scanner" in
minimumReleaseAgeExcludes failed the install, and it couldn't tell an
unremovable scanner from an unrelated value that mentions one.

Now detection and verification go through Bun.TOML.parse: the copy must equal
the original minus install.security.scanner (empty tables count as absent),
or the install fails. The check runs with --config=/dev/null so the repo's own
bunfig.toml can't break it before it reports.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant