Skip to content
Merged
28 changes: 28 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,34 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).

## [Unreleased]

### Fixed
- `changed_files` diff-only mode always resolved to zero files in the pre-built
Docker GitHub Action: the container runs as root while the checkout is owned
by the runner user, so git's ownership check refused every diff lookup, the
scope silently resolved to nothing, and the scanners skipped with a green
run. Git subprocesses now mark the scan workspace as `safe.directory` via
command-scope `GIT_CONFIG_*` environment entries. No config files are
touched, and caller-provided `GIT_CONFIG_*` entries (including the previously
documented workaround) are preserved. The same mismatch broke git-based
repository/branch/commit and default-branch discovery in local Docker runs;
those lookups are covered by the same change.
- A failed `changed_files` diff resolution is no longer indistinguishable from
an empty diff. Git errors are captured and logged (instead of discarded), and
when the scope cannot be resolved — unreadable repository, unresolvable base
ref (e.g. a shallow fetch without the base), or `pr` mode with no base ref —
Socket Basics now **falls back to a full-repo scan with a prominent warning**
rather than skipping every scanner and reporting a green run that scanned
nothing. A genuinely empty diff (e.g. a delete-only PR) still keeps the empty
scope and skips as before. One deterministic case fails fast instead of
falling back: a **shallow checkout** that cannot resolve the base ref exits
with a configuration error naming the fix (`fetch-depth: 0`), since it would
otherwise full-scan every PR — slow or OOM-prone on large repositories.

### Added
- The resolved `changed_files` scope is now logged on every scoped run: file
count at INFO, the full file list at DEBUG — so an empty diff and a failed
lookup are visible and distinguishable in run logs.

## [3.0.0] - 2026-08-06

Major release: Trivy-backed scanning returns, now built and published through
Expand Down
28 changes: 28 additions & 0 deletions docs/github-action.md
Original file line number Diff line number Diff line change
Expand Up @@ -324,6 +324,34 @@ jobs:
> nothing rather than falling back to the whole repo. To scan an explicit file
> list regardless of git state, use the `scan_files` input instead.

> [!NOTE]
> **When the diff cannot be resolved** — the checkout is unreadable, or the
> base branch is missing (most commonly a shallow clone without
> `fetch-depth: 0`) — Socket Basics logs a warning naming the underlying git
> error and **falls back to a full-repository scan** rather than silently
> scanning nothing. This is deliberate fail-toward-scanning behavior for a
> security gate, and it comes with two tradeoffs worth planning for:
>
> - On very large repositories an unexpected full scan can be slow or exhaust
> CI memory. If the fallback warning appears on **every** PR, the cause is
> almost always the missing `fetch-depth: 0` — fix the checkout rather than
> sizing up the runner.
> - The full scan reports **pre-existing** findings, not just the PR's change,
> so a repo-wide checkout misconfiguration shows up as large PR comments or
> failing checks on every PR until corrected. The run log's warning names
> the actual git error — read it before triaging the findings.
>
> **Exception — shallow checkouts fail fast instead.** If the base branch is
> missing *because the checkout is shallow* (the classic missing
> `fetch-depth: 0`), the failure is deterministic — every PR would full-scan —
> so Socket Basics exits with a configuration error naming that one-line fix
> rather than falling back.
>
> A genuinely *empty* diff (e.g. a delete-only PR) still skips the scanners;
> the fallback triggers only when resolution **fails**. The resolved file
> count is logged on every scoped run, so an empty diff and a failed lookup
> are always distinguishable in the logs.

## PR Comment Customization

Socket Basics automatically posts enhanced PR comments with **smart defaults that work out of the box** — clickable file links, collapsible sections, syntax highlighting, CVE links, CVSS scores, and auto-labels are all enabled by default.
Expand Down
17 changes: 17 additions & 0 deletions docs/parameters.md
Original file line number Diff line number Diff line change
Expand Up @@ -120,6 +120,23 @@ PR), the scanners are skipped rather than falling back to scanning the whole
repository. For PR/`auto`/`pr` modes, check out with full history (e.g.
`actions/checkout` with `fetch-depth: 0`) so the base branch is available.

If the diff **cannot be resolved**, behavior depends on why:

- **Shallow checkout with a missing base ref** (the classic missing
`fetch-depth: 0`): deterministic misconfiguration — the run **fails fast
with a configuration error** naming the fix, instead of full-scanning every
PR.
- **Any other resolution failure** (unreadable repository, non-shallow missing
ref): a warning with the underlying git error is logged and the scan **falls
back to the whole workspace** instead of silently scanning nothing. On large
repositories a surprise full scan can be slow or hit CI limits and reports
pre-existing findings, so treat the warning as the signal and fix the root
cause.

The resolved scope is logged on every run (file count at INFO, full file list
at DEBUG), so an empty diff and a failed lookup are distinguishable in run
logs.

**Example:**
```bash
socket-basics --changed-files auto
Expand Down
Loading