Repository navigation
chore: sync published workspace versions - #582
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Temporarily closing and immediately reopening this generated PR to trigger the normal pull-request CI with the maintainer account. The workflow-created PR currently has external checks only; integration will wait for the required repository and infrastructure checks on this exact head. |
|
ty-everett
left a comment
There was a problem hiding this comment.
Approved after complete review of 7515cf2d605228966d83f5dd217649ddf7df0798, including the clean merge of SDK publication record #583. The PR updates eight infrastructure manifests/locks and generated service-version documentation. All 15 changed locked BSV artifacts exactly match the version and SHA-512 integrity of the independently verified protected releases 35909323275 and 35912232040; no other transitive package entry or runtime source is changed. Service versions receive patch bumps; SDK/Toolbox compatible ranges resolve to already published artifacts. Local generated facts, dependency-release governance and repository health pass. Exact-head CI, eight infrastructure lanes, seven runtime image/security lanes, CodeQL, the zero-new-Sonar gate and merge gate pass. Review threads and CodeQL alerts are empty; no exception or suppression was added. This source integration does not publish container images or deploy any operator workload; those remain distinct qualified steps.
|
Exact-head approval and every applicable check are now complete on 7515cf2, with base 4fb7f3e. The remaining normal-merge blocker is the required codecov/patch status, which is absent for this manifest/lock/generated-documentation-only change. Using the maintainer-authorized administrative merge after the full infrastructure/runtime gates passed; no failed test, vulnerability finding or unresolved review is bypassed. |



Program and scope
Impact
Affected services and intended patch versions are the changed infra package manifests in this PR.
Verification
Security and dependencies
Dependency evidence
Release and operations
The protected infrastructure release builds Linux/amd64 images, rejects high and critical findings, publishes immutable GHCR tags, and attaches SBOM, provenance, and signature evidence after merge. Existing immutable tags remain the rollback path.
Completion evidence