All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog.
Findings for the hardcoded-credential rules now report where a credential is without reproducing what it is. Minor rather than patch: the snippet a finding carries changes for every consumer that reads it, and the release adds a new rule-metadata key.
No configuration change is required, but findings differ on the first run after upgrading.
codeSnippetcontent changes for the credential rules. The field keeps the assignment target and surrounding syntax where that is unambiguous, as well as the file and line, and masks the literal. A baseline keyed on exact snippet text will not match; key on rule ID plus location instead. Rules whose match is not a credential are unaffected. (#119)- The same applies to
detailedReport.contentanddataflowTrace. Both quote source lines and both are masked on the same terms. (#119) - A finding's
descriptioncan also change. OpenGrep expands metavariables into a rule's message before returning a result, so a message quoting the matched value carried it too. Expanded metavariables are masked for the credential rules. (#119) - Masking is deliberately conservative in several visible places.
define('SECRET', '...')masks the constant name along with the value, andpassword: "admin"hides which default was used. Ambiguous unquoted values can also mask the rest of a statement or line rather than risk treating part of the credential as source syntax. Rule ID, file and line still identify the finding in each case. (#119)
- A finding's snippet no longer reproduces the value it reports. A SAST
finding's
codeSnippetis the source line the rule matched. For nearly every rule that line is the code the finding is about; for the hardcoded-credential rules it contains the credential, so the finding carried the value into.socket.facts.json, the uploaded facts and the configured notifiers. Snippets for those rules now keep the assignment target and syntax when safe, keep the file and line, and mask the literal's contents. This covers 20 rules across all fifteen bundled language rule sets, not only the Python and JavaScript ones:*-hardcoded-secret(s),*-hardcoded-credentials,*-hardcoded-password-default,*-default-credentials,*-plain-text-password,*-weak-jwt-secretand*-empty-password. Rules whose match is logic keep their snippets verbatim, and a complete assigned call with a literal argument is treated as code, souser.password = request.form.get('password')keeps its expression while the quoted argument is masked. (#119) - Every snippet, dataflow-trace step, rule message and detailed report, whatever rule produced it, is now masked of values matching a well-known credential format: AWS key IDs, GitHub tokens, Stripe keys, Slack tokens, Google API keys, npm and PyPI tokens, JWTs, PEM private key bodies, and credentials in a URL authority. A rule unrelated to secrets can still match a line that carries one. (#119)
- TruffleHog's
redactedValuekept the first and last four characters of any value longer than eight, which left most of a short password readable. Values under sixteen characters are now masked in full. (#119) - TruffleHog no longer scans the facts file the run writes. That file lands inside the scan target, so a previous run's output was on disk during the walk and its contents were reported as findings of their own, pointing at the output file rather than the source line. (#119)
- socketdev 3.5.0 -> 3.6.0 in the lockfile. The
>=3.5.0floor inpyproject.tomlis unchanged. (#117) load_explicit_env_configbuilds its "API key sources detected" debug line by iterating a tuple of variable names rather than a dict of presence booleans. The line is unchanged, including the exclusion of an exported-but-empty variable. (#119)
- A
redactrule-metadata key. Set it on a custom SAST rule to mark the match as a credential, or to opt a rule out; without it, the rule name decides. (#119)
Small release pairing a CLI parity addition with a notification fix. The fix changes behavior for anyone who configured a GitHub token through the Socket dashboard: PR comments that were silently never posted will start posting.
--scan-all/--no-scan-allCLI flags, the command-line equivalent of thescan_allaction input,INPUT_SCAN_ALLand thescan_allJSON/dashboard key.scan_allwas the one scope setting the 3.2.0 parity pass missed, so the remediation the unresolvable-scope error recommends was not reachable from the CLI at all.--no-scan-allforces the fail-closed behavior back on for a single run whenscan_allis already set elsewhere; passing neither flag leaves the configured value untouched. (#115)
- The unresolvable
changed_fileserror now names the remediation for each interface (--scan-all, thescan_allaction input,INPUT_SCAN_ALL, a--configJSON or dashboard key) instead of saying only "set scan_all". (#115) - Socket Python CLI 2.8.0 -> 2.9.0 in the heavy and app-tests images.
- GitHub PR notifier now reads the
github_tokennotifier parameter. The parameter is declared asgithub_tokeninnotifications.yaml, which is the key the notification manager resolves dashboard configuration and theGITHUB_TOKENenvironment variable into, but the notifier looked uptoken. A token supplied through dashboard configuration enabled the notifier without reaching the GitHub API call, so the run loggedno GitHub token availableand posted nothing. Environment-variable configuration was unaffected, since the notifier fell back to readingGITHUB_TOKENdirectly.tokenis still accepted for callers that construct the notifier themselves. (#114)
Scanner accuracy release. TruffleHog secret verification and the Java SAST rule set were both fixed, and both change which findings a scan produces — read the upgrade notes before rolling this out to a pipeline that gates on findings.
Nothing here requires a configuration change, but expect different results on the first run after upgrading.
- TruffleHog secrets can now block a run. With
trufflehog_show_unverifiedoff (the default), the connector passed--no-verification, which disabled verification outright instead of filtering to verified results. Severity is derived from each finding'sVerifiedflag, so every result came back unverified, low severity and non-blocking: on the default path no secret could ever block a run, the exact inverse of intent. Verification now always runs and the setting only selects result types, so a real leaked credential is reported as critical and blocking. (#110) - TruffleHog verification reaches third-party endpoints. Verification is a
live check: candidate credentials are sent to the issuing provider's
validation endpoint on every scan. This is TruffleHog's own default behavior,
but it is new for runs with
trufflehog_show_unverifiedoff. Egress restricted runners should account for it. (#110) - A TruffleHog scan that cannot run now fails the run. A non-zero exit, a
missing binary or a source error was logged and converted into an empty clean
result, so a broken install or a malformed exclude pattern was
indistinguishable from a repository with no secrets. These now fail with
TruffleHog's exit code and stderr — the same fail-closed idiom as an
unresolvable
changed_filesscope in 3.1.0. (#110) - Java SAST findings shift substantially, in both directions. Twelve rules were rewritten (see Fixed). Existing Java baselines will lose most of their current findings and gain new ones at call sites the old patterns could never match, so re-baseline instead of diffing against a previous run. (#112)
--versionand--socket-orgCLI flags.--socket-orgis the command-line equivalent of thesocket_orgaction input and theSOCKET_ORGenvironment variable; the API key remains environment-only. (#111)- Action inputs for settings that previously existed only as CLI flags or
environment variables:
verbose,console_tabular_enabled,console_json_enabled,jira_url,jira_project,ms_sentinel_shared_key,opengrep_notification_methodandtrufflehog_notification_method. The olderserver,project,ms_sentinel_keyandnotification_methodnames remain as aliases. (#111) - A Name Mapping section in
docs/parameters.mdlisting every setting as CLI flag, action input, environment variable and JSON key, generated fromconnectors.yaml,notifications.yamlandaction.yml, plus a test that keepsaction.ymland the parameter declarations in step. (#111) - Documentation for the
-heavyimage variant and for when the standard image is the right choice. (#111) - Java SAST:
java-xss(CWE-79) andjava-xpath-injection(CWE-643) taint rules; an OWASP Benchmark scorer (scripts/score_owasp_benchmark.py) with the method and results indocs/java-sast-benchmark.md; and annotated Java rule regression fixtures undertests/fixtures/opengrep/java, which CI now runs against the opengrep release pinned in the Dockerfile. (#112) scripts/check_release_docs.pyalso verifies that action references use an exact release tag and that the bundled scanner versions quoted in the guides match the Dockerfile pins;--writeupdates both. (#111)
- TruffleHog reports verified and unknown results by default, and adds
unverified results only when
trufflehog_show_unverifiedis on. Verified findings are critical and blocking; unknown and unverified findings remain low and non-blocking. Boolean strings are now coerced wherever the setting comes from, so a Socket dashboard config supplying"false"is no longer read as on. (#110) - Socket Python CLI 2.7.0 → 2.8.0 in the heavy and app-tests images. (#112)
- The
workspaceandGITHUB_API_URLGitHub Action inputs. Neither had an effect: the action always scansGITHUB_WORKSPACE, andGITHUB_API_URLis provided by the runner. Workflows that still set them receive an "Unexpected input" warning and otherwise behave as before. (#111) docs/alert-quality-improvement-plan.md, a draft working document from a hackathon branch. The plan itself is now tracked separately. (#111)
- Java SAST precision and recall. Twelve rules were rewritten after a
customer evaluation reported roughly 90% false positives. Two systematic
defects drove the recall gap: patterns written with simple type names never
matched fully qualified call sites, and crypto rules matched exact algorithm
literals instead of transformation strings. On OWASP Benchmark v1.2 recall
rises from 13.2% to 71.3% while precision improves from 64.5% to 76.7%; on
six mature open source projects (~17,400 files) findings drop by 92%, and the
four lint-style rules (
java-empty-catch-block,java-system-out-usage,java-reflection-injection,java-hardcoded-credentials) report nothing there — the first three alone produced 74% of the original noise. About a quarter of that volume drop comes from new test, benchmark and example path exclusions rather than rule logic;docs/java-sast-benchmark.mdrecords the method, the per-category numbers and the caveats. (#112) - Java SAST false positives removed along the way:
RSA/ECB/...is no longer a weak cipher; a hardened cookie no longer hides an unhardened neighbour; parameterizedJdbcTemplate/PreparedStatementcalls, the four-argument LDAPsearch(base, filter, args, controls)form,MessageDigest.update(), and thePath.startsWith/canonical-path containment idioms are no longer reported; SnakeYAMLSafeConstructorloads are excluded (including the 2.0LoaderOptionsform) whileloadAs/loadAllare now sinks;"10.0.0.1"is reported as a hardcoded IP and"10.2.3"is not. (#112) - The Sentinel and Sumo Logic notifiers now read
ms_sentinel_workspace_id,ms_sentinel_keyandsumologic_endpointfrom CLI flags, action inputs and dashboard configuration, in addition to theMS_SENTINEL_*andSUMO_LOGIC_HTTP_SOURCE_URLenvironment variables. (#111) - Documentation consistency pass across the GitHub Action, Docker and local
installation guides. CLI examples use the flag names that
socket-basics --helpprints. Docker examples keep the facts file inside the workspace so the dashboard upload succeeds, and show the environment variables needed for PR comments outside GitHub Actions. The GitHub Action guide reflects the bundled Trivy scanner, lists only declared inputs, and passes discovered Dockerfiles through in the auto-discovery example. JSON configuration examples use the keys the loader reads, the S3 variable names and--configprecedence match the code, GitLab and Jenkins examples override the image entrypoint, pre-commit hook examples use the published image name, and the installation guide states the Python 3.10 requirement and the npm install path for the Socket CLI. New guidance covers large repositories and facts-file size. (#111) - TruffleHog parameter documentation: exclude paths accept files and globs, not
only directories, and
trufflehog_show_unverifiedwidens result types rather than toggling verification. A JSON configuration example named a nonexistentshow_unverifiedkey. (#110)
pr_comment_enabled(defaulttrue): set tofalseto run scans without posting or updating the pull request comment. Findings still reach the Socket dashboard, since the facts upload runs before any notifier. (#97)pr_comment_collapse_all(defaultfalse): starts the collapsible OpenGrep (SAST) and Socket Tier 1 sections collapsed, including critical findings. Flat-table outputs (TruffleHog, Trivy Dockerfile) are unaffected. (#97)- Negative
--no-*forms for every default-true boolean CLI flag, e.g.--no-pr-comment. (#97) - The resolved
changed_filesscope is logged on every scoped run — file count at INFO, full list at DEBUG — so an empty diff and a failed lookup are distinguishable in run logs. (#105) scan_allis now a declared action input, and doubles as the fail-open escape hatch forchanged_files: when the scope cannot be resolved, widen to a full-repo scan with a warning instead of failing. Every enabled scanner widens consistently on that path. (#98, #105)
- Behavioral: a
changed_filesscope that cannot be resolved (unreadable repository, missing base ref, shallow checkout with no base) now fails the run with a configuration error instead of scanning. Previously this exited green having scanned nothing. Pipelines with a broken diff-only setup will start failing on the first run after upgrading — read the error, which names the underlying git problem. Setscan_allto widen instead of failing. (#98, #105) - A successfully resolved
changed_filesscope is now authoritative overscan_all, which previously overrode it.scan_allapplies only on the failure path. A genuinely empty diff (e.g. a delete-only PR) still skips the scoped scanners. (#98) - Socket toolchain refresh: Socket npm CLI 1.1.154 → 1.1.165 in every image, and Socket Python CLI 2.6.3 → 2.7.0 in the heavy and app-tests images. The socketdev Python SDK is already current at 3.5.0.
- Notifier parameters from
notifications.yamlnow take CLI overrides through the same path as connector parameters, fixing flags that parsed but never reached the effective config. Absent boolean flags resolve to "unset" rather thanfalse, so CLI defaults no longer clobber environment, JSON, or dashboard config. (#97)
changed_filesdiff-only mode resolved to zero files on every run of the pre-built Docker action, so scans exited green having scanned nothing: the container runs as root over a runner-owned checkout, and git refuses to read a repository it does not own. Git subprocesses now mark the workspacesafe.directoryvia command-scopeGIT_CONFIG_*entries, and any caller-suppliedGIT_CONFIG_*entries are preserved. The same mismatch broke git-based repository, branch, and commit discovery in local Docker runs. (#105)changed_fileswas only resolved for CLI-built configs, so environment, JSON, and dashboard configs silently scanned the whole repository, and a literal"auto"was iterated character by character into an empty scope. Every config source now runs through one resolver. (#98)- Pull request base detection falls back to
pull_request.base.sha/.reffrom the event payload whenGITHUB_BASE_REFis unset, coveringpull_request_target,pull_request_reviewandpull_request_review_comment.issue_commentcarries no usable base and now warns to passGITHUB_BASE_REFfrom the workflow. (#98) - TruffleHog and Trivy no longer substitute their own staged-file scope when an
explicit
changed_filesrequest is in effect. Trivy's Dockerfile scan skips when no Dockerfile changed, and TruffleHog drops changed paths that no longer exist on disk. (#98)
- core-tool-watch reconciles one canonical
core-tool-driftissue onmainpushes, tracks the Socket Python and npm CLIs plusDockerfile.heavy, and reads Trivy releases fromghcr.io/socketdev/trivy. The npmsocketCLI is pinned in every image, and Docker publish no longer authors a GitHub Release. (#104) - Release prep keeps action and image references in README and
docs/**in sync with the release version; 73 stale2.0.3references normalized. (#106) - Dependency updates: pyyaml (#107), docker/setup-buildx-action (#108).
- app-tests image refreshes
socketsecurityindex metadata on install, so a stale cached index cannot make a freshly published pin look nonexistent.
Major release: Trivy-backed scanning returns, now built and published through Socket's own supply chain.
- Container image and Dockerfile scanning (Trivy) restored in the pre-built
GitHub Action and Docker images. Trivy now comes from a Socket-built
distribution — rebuilt from unmodified upstream source (v0.73.0) by
Socket's own release pipeline and pinned by digest in the Dockerfiles
(
TRIVY_IMAGEbuild arg; overridable for builds without registry access). latestandlatest-heavyfloating Docker tag aliases. Exact version tags remain immutable registry-side; pin an exact version or digest for reproducible pipelines.- End-to-end integration test for the Trivy connector (fixture Dockerfile scan
through
--dockerfiles), plus smoke-test assertions that the bundled trivy matches the pinned version and can execute the connector's scan path.
- Behavioral (the reason this is a major): Trivy-backed scanning was
intentionally disabled in the 2.x pre-built images following the March 2026
upstream Trivy supply-chain incident, and documented as such throughout the
project. With this release it is deliberately re-enabled: configurations
that set Trivy parameters (
--images,--dockerfiles,trivy_vuln_enabled, …) will begin producing container/Dockerfile findings again, so pipelines that gate on findings should expect new results on the first run after upgrading. - OSS toolchain refresh: TruffleHog 3.96.0, OpenGrep v1.26.0 (SAST rule
updates may shift findings), uv 0.12.1, gosec v2.28.0, Go 1.26.5
(app-tests), Socket CLI 2.6.3 (heavy image), and the socketdev Python SDK to
3.5.0 (typed fail-closed batch purl parameters; adopted by core-tool-watch in
a follow-up). Runtime bases (
python:3.12,node:22) are unchanged. - Docker Hub publish credentials are now scoped to the
publishGitHub environment (deployment restricted tomainandv*tags) instead of repo-level secrets. - Manual re-publish (
workflow_dispatch) is recovery-only: re-pushing an already-published version tag is rejected by the registry's immutable-tag rule. - Dependabot no longer tracks the trivy base image; Trivy updates flow through Socket's release process, never independent bumps.
- CI: GitHub Actions dependency updates (#95, #96).
- The app-tests image had been unbuildable since the repository layout
migration (stale source references, wrong build context, dereferenced npm
symlinks, corrupt
uv.lock) — repaired and building in CI again. - Documentation: removed the now-outdated "temporarily ships without Trivy"
notices repo-wide (they described the intentional 2.x posture); APT install
instructions now use upstream's
genericdistribution (required since Trivy v0.72.0); warnings against Trivy 0.69.4–0.69.6 retained for native installs.
- Fixed TruffleHog secret scanning when
trufflehog_exclude_diris configured: all entries now pass through one filter file and are honored for changed-file and explicit-file scans. Previously, configured values could be interpreted as filter filenames and fail or alter scans. - Added glob-pattern support for exclusions such as
**/appsettings.*.json, with matching anchored beneath the workspace and root-relative globs kept distinct from recursive**globs. - Normalized exclusion entries before pattern generation so dot segments and repeated path separators behave consistently.
- Fixed exclusion matching when the configured workspace is the filesystem root.
- Normalized in-workspace TruffleHog finding paths relative to the workspace so host paths do not appear in facts and component identifiers remain stable across runs, working directories, and operating systems.
- Publish multi-arch Docker images for
linux/amd64andlinux/arm64. - Add a heavy image variant (
socket-basics:<version>-heavytag suffix) bundling Socket Basics with the pinned Python Socket CLI.
- Normalize manual Docker release tag inputs before checkout.
- core-tool-watch now opts into fail-closed Socket purl batch semantics
(
poll+alerts), so fresh-but-unanalyzed pins surface as labeled pending/not-found failures instead of silently dropped rows.
- Diff-only scan scoping now applies to SAST/OpenGrep via
changed_filesandscan_files. - Added GitHub Action inputs for
changed_filesandscan_files.
- Delete-only changed-file scans now skip instead of falling back to a full workspace scan.
- Updated parameter docs to reflect SAST/OpenGrep diff-only scoping.
- fix: Harden GHA workflows by @reberhardt7 in #58
- docs: cleanup docs guidance, additional workflow hardening by @lelia in #60
- fix(rules): improve precision of 4 high-FP dotnet opengrep rules by @dc-larsen in #63
- @reberhardt7 made their first contribution in #58
Full Changelog: https://github.com/SocketDev/socket-basics/compare/v2.0.2...v2.0.3
- Bump urllib3 from 2.5.0 to 2.6.3 by @dependabot[bot] in #21
- Removed qualifiers by @dacoburn in #1
- Doug/fix trivy socket results by @dacoburn in #2
- Fix action.yml configuration and add GitHub token by @dacoburn in #3
- Update action.yml description for clarity by @dacoburn in #4
- docs: fix link by @ahmadnassri in #5
- Added back in transitive logic and fixed format of integration messages by @dacoburn in #6
- Fixed documentation and version checks by @dacoburn in #7
- Added action inputs by @dacoburn in #8
- Updated examples with PR check and pinning to commit hashes by @dacoburn in #9
- Fixing issue of the git detection logic not using the workspace or GI… by @dacoburn in #10
- Doug/add node and socket back into container by @dacoburn in #11
- Fix for caching result by @dacoburn in #12
- Doug/improve default sast ruleset by @dacoburn in #13
- Fixed hard coded detection for golang by @dacoburn in #14
- Fixing regression in rule name by @dacoburn in #15
- Remove non-existent install options from local-installation.md by @graydonhope in #16
- Fix: Empty CLI string defaults no longer override env/API config by @dc-larsen in #17
- Bump version to 1.0.26 by @dc-larsen in #20
- docs: add Dockerfile auto-discovery workflow pattern by @dc-larsen in #25
- Add scan_type parameter to full scan API calls by @mtorp in #24
- Upgrade 1.0.28 by @mtorp in #27
- feat: add SKIP_SOCKET_REACH and SKIP_SOCKET_SUBMISSION env vars for Node.js Socket CLI integration by @jdalton in #29
- Remove CODEOWNERS entry for @SocketDev/eng by @Raynos in #31
- Improve usefulness of generic output by @trevnorris in #28
- Pin trufflehog to known-good version tag by @lelia in #32
- Fix notifiers reading repo/branch from wrong source by @dc-larsen in #30
- Fix: Jira dashboard config params not reaching notifier by @dc-larsen in #22
- Update CODEOWNERS to reference GitHub Enterprise team name by @lelia in #33
- Enhance GitHub PR comment experience by @lelia in #26
- Fix
CODEOWNERSsyntax by @lelia in #35 - Fix webhook notifier not reading URL from dashboard config by @dc-larsen in #34
- Final
CODEOWNERSupdate with new team name by @lelia in #36 - Bump Trivy from v0.67.2 to v0.69.2 by @dc-larsen in #39
- Bump version to prep for release by @lelia in #40
- Pin
opengrepversion, add Docker smoketest by @lelia in #41 - Add GitHub workflow for
pytestby @lelia in #42 - Fix Slack and MS Teams notifiers not reading URL from dashboard config by @dc-larsen in #37
- Add structured findings to webhook payload by @dc-larsen in #38
- feat: 🐳 multi-stage Docker builds, immutable release pipeline,
CHANGELOGautomation by @lelia in #46 - fix(ci): add conventional commit prefixes to Dependabot config by @lelia in #53
- fix(ci): support breaking change indicator (!) in commit-lint pattern by @lelia in #54
- fix(ci): accept full tag name in workflow_dispatch, drop auto-v-prefix by @lelia in #55
- feat!: switch to pre-built GHCR images by @lelia in #48
- fix: remove trivy from Docker build while assessing compromise impact by @dacoburn in #56
- chore: fix release and updater script by @lelia in #57
- @dacoburn made their first contribution in #1
- @ahmadnassri made their first contribution in #5
- @graydonhope made their first contribution in #16
- @dc-larsen made their first contribution in #17
- @mtorp made their first contribution in #24
- @jdalton made their first contribution in #29
- @Raynos made their first contribution in #31
- @dependabot[bot] made their first contribution in #21
- @trevnorris made their first contribution in #28
- @lelia made their first contribution in #32
Full Changelog: https://github.com/SocketDev/socket-basics/commits/v2.0.2