Repository navigation
Conversation
taraxvoid
commented
Oct 9, 2026
Owner
- feat(ci): skip the bunfig security scanner in CI by default
- fix(bun-install): verify the scanner-free bunfig by parsing it, not grep
Socket's bun scanner calls a third-party API on every install, so a network blip or API change can fail an otherwise-green build, and reruns of the same commit aren't guaranteed to agree. Local installs keep running it. - actions/bun-install: `bun install --frozen-lockfile` with a `socket-scanner` input (default 'false'). When off, installs with a scanner-free copy of bunfig.toml via `--config=` (replaces, not merges; other settings still apply), leaves a notice, and fails closed on a scanner it can't strip. - site-ci.yml: same `socket-scanner` input (default false); the bun install step inlines the action's script, kept identical by a test. pnpm unchanged. - ci.yml: voidflow's own unit-test install goes through the action. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The grep check was a heuristic: a package like "foo-scanner" in minimumReleaseAgeExcludes failed the install, and it couldn't tell an unremovable scanner from an unrelated value that mentions one. Now detection and verification go through Bun.TOML.parse: the copy must equal the original minus install.security.scanner (empty tables count as absent), or the install fails. The check runs with --config=/dev/null so the repo's own bunfig.toml can't break it before it reports. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.