Bump pinned @coana-tech/cli to 15.10.50 - #369
Closed
socket-pr-bot[bot] wants to merge 1 commit into
Closed
socket-pr-bot[bot] wants to merge 1 commit into
socket-pr-bot[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
Superseded by #370. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
@coana-tech/clifrom15.10.48to15.10.50and bumps the Python CLI version to2.9.7.Engine changelog
For what is included in this engine release, see the reachability analysis changelog.
Note
Low Risk
Routine pinned-engine and package version bump with no Python CLI logic changes; reachability behavior may shift only per the external Coana release notes.
Overview
Releases Socket Python CLI 2.9.7 by bumping the shipped default reachability engine from
@coana-tech/cli15.10.48 to 15.10.50 (DEFAULT_COANA_CLI_VERSIONinreachability.py), which is what--reachuses when--reach-versionis omitted.Version strings are aligned in
pyproject.toml,socketsecurity/__init__.py, anduv.lock, with CHANGELOG and cli-reference updated to document the new pin and point readers at the reachability analysis changelog for engine details.Reviewed by Cursor Bugbot for commit 2af5a01. Configure here.