Skip to content

deps(engine): bump @socketsecurity/cli from 1.1.176 to 1.1.179 - #182

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/socketsecurity/cli-1.1.179
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/socketsecurity/cli-1.1.179

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps @socketsecurity/cli from 1.1.176 to 1.1.179.

Release notes

Sourced from @​socketsecurity/cli's releases.

v1.1.179

What's Changed

Full Changelog: SocketDev/socket-cli@v1.1.178...v1.1.179

v1.1.178

What's Changed

Full Changelog: SocketDev/socket-cli@v1.1.176...v1.1.178

v1.1.177

What's Changed

Full Changelog: SocketDev/socket-cli@v1.1.176...v1.1.177

Changelog

Sourced from @​socketsecurity/cli's changelog.

1.1.179 - 2026-09-24

Changed

  • Updated the Coana CLI to v 15.10.55.
  • Generated Maven, Gradle and sbt .socket.facts.json files are now substantially smaller, making uploads for large JVM projects faster and more reliable.

Fixed

  • Running socket manifest maven or socket manifest scala on a directory without a build now fails with a clear message, instead of crashing (Maven) or silently producing a bogus Socket facts file (sbt).

1.1.178 - 2026-09-23

Changed

  • Updated the Coana CLI to v 15.10.49.

Fixed

  • Fixed Maven manifest generation so a dependency is no longer emitted as an orphaned component when Maven's conflict resolution keeps it under a test or provided parent while its effective scope is compile. These components previously produced spurious "orphaned component not reachable from any direct dependency" alerts.
Commits
  • 59f8ce8 chore(release): 1.1.179
  • f49bdfc fix(manifest): fail clearly on a directory without a Maven or sbt build (#1560)
  • d229c8e fix(manifest): merge JVM facts components by coordinate (#1557)
  • f7ef5c0 upgrading coana to version 15.10.54 (#1558)
  • 7fa6bbc fix(types): patch the registry editor declaration directly
  • 11a801a fix(optimize): declare registry json editor method
  • ba70d71 docs(release): describe v1 dry-run artifact writes
  • 5584833 fix(ci): verify uv downloads and remove diagnostic requests
  • 2408a9c fix(ci): scope v1 release tokens to this repository
  • 2aaa2f6 chore(release): 1.1.178
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@socketsecurity/cli](https://github.com/SocketDev/socket-cli) from 1.1.176 to 1.1.179.
- [Release notes](https://github.com/SocketDev/socket-cli/releases)
- [Changelog](https://github.com/SocketDev/socket-cli/blob/v1.1.179/CHANGELOG.md)
- [Commits](SocketDev/socket-cli@v1.1.176...v1.1.179)

---
updated-dependencies:
- dependency-name: "@socketsecurity/cli"
  dependency-version: 1.1.179
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, engine. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​socketsecurity/​cli@​1.1.176 ⏵ 1.1.1799910010098100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants