Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
93f420b
feat(manifest): name JVM Socket facts files after their build
jfblaa Oct 7, 2026
afeceb0
feat(manifest): give each build project its own facts component
jfblaa Oct 7, 2026
fb930e2
Merge remote-tracking branch 'origin/v1.x' into jfblaa/named-socket-f…
jfblaa Oct 8, 2026
649eb2f
chore(manifest): trim comments that restate the code
jfblaa Oct 8, 2026
6eb4c61
fix(manifest): judge recursive coverage against the build root
jfblaa Oct 8, 2026
7594c03
feat(scan): recognise any *.socket.facts.json and keep reachability r…
jfblaa Oct 8, 2026
3e2edef
fix(manifest): write JVM Socket facts into the build's own root
jfblaa Oct 8, 2026
3cbc05c
feat(manifest): give each JVM build project its own id and facts comp…
jfblaa Oct 8, 2026
d4e6040
Merge branch 'jfblaa/facts-project-ids' into jfblaa/named-socket-fact…
jfblaa Oct 8, 2026
ef9ed6f
fix(scan): keep bare .socket.facts.json in reachability input
jfblaa Oct 8, 2026
e02a9a7
Merge branch 'jfblaa/facts-any-name' into jfblaa/facts-build-root
jfblaa Oct 8, 2026
d9fedb4
Merge branch 'jfblaa/facts-build-root' into jfblaa/facts-project-ids
jfblaa Oct 8, 2026
7b44a79
Merge branch 'jfblaa/facts-project-ids' into jfblaa/named-socket-fact…
jfblaa Oct 8, 2026
67767fe
docs(changelog): describe the project-merging problem the facts ids fix
jfblaa Oct 8, 2026
7b9d2f3
Merge branch 'jfblaa/facts-project-ids' into jfblaa/named-socket-fact…
jfblaa Oct 8, 2026
2d27284
Merge remote-tracking branch 'origin/v1.x' into jfblaa/named-socket-f…
jfblaa Oct 8, 2026
98391c7
Merge remote-tracking branch 'origin/v1.x' into jfblaa/named-socket-f…
jfblaa Oct 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
## [Unreleased]

### Changed
- Socket facts for Maven, Gradle and sbt builds are now written per build — `pom.xml.socket.facts.json` (named after the POM Maven runs on, so `-f other-pom.xml` gets its own), `gradle.socket.facts.json` and `sbt.socket.facts.json` — so builds sharing a directory no longer overwrite each other. Delete any `.socket.facts.json` an earlier run left behind.
- Reachability scans no longer feed a leftover `.socket.facts.json` report from an earlier run back into the analysis.
- Updated the Coana CLI to v `15.12.4`.

## [1.6.2](https://github.com/SocketDev/socket-cli/releases/tag/v1.6.2) - 2026-10-09
Expand Down
2 changes: 1 addition & 1 deletion src/commands/manifest/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -153,7 +153,7 @@ underlying flow is identical to the gradle subcommand.

## socket manifest maven [beta]

Generates a Socket facts file (`.socket.facts.json`) from a Maven `pom.xml`
Generates a Socket facts file (`pom.xml.socket.facts.json`) from a Maven `pom.xml`
project, using `mvn` (override with `--bin`, e.g. a project `./mvnw` wrapper).
Pass extra options through to maven with `--maven-opts` (e.g.
`--maven-opts="-P release -s settings.xml"`).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,10 @@ const config: CliCommandConfig = {
$ ${command} [options] [CWD=.]

Recursively walks CWD, discovers independent gradle, sbt, and maven build
roots, and generates a Socket facts SBOM (.socket.facts.json) for each,
roots, and generates a Socket facts SBOM for each
(pom.xml.socket.facts.json, gradle.socket.facts.json, or
sbt.socket.facts.json, so builds sharing a directory never overwrite each
other),
skipping subproject/reactor-module directories a parent build root already
covers. Unlike \`socket manifest auto\`, this looks beyond CWD itself.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,10 @@ describe('socket manifest dynamic-sbom-inference', async () => {
$ socket manifest dynamic-sbom-inference [options] [CWD=.]

Recursively walks CWD, discovers independent gradle, sbt, and maven build
roots, and generates a Socket facts SBOM (.socket.facts.json) for each,
roots, and generates a Socket facts SBOM for each
(pom.xml.socket.facts.json, gradle.socket.facts.json, or
sbt.socket.facts.json, so builds sharing a directory never overwrite each
other),
skipping subproject/reactor-module directories a parent build root already
covers. Unlike \`socket manifest auto\`, this looks beyond CWD itself.

Expand Down
10 changes: 5 additions & 5 deletions src/commands/manifest/cmd-manifest-gradle.mts
Original file line number Diff line number Diff line change
Expand Up @@ -38,12 +38,12 @@ const config: CliCommandConfig = {
facts: {
type: 'boolean',
description:
'Emit a Socket facts JSON file (`.socket.facts.json`) describing the resolved dependency graph. This is the default; pass `--pom` to generate `pom.xml` files instead',
'Emit a Socket facts JSON file (`gradle.socket.facts.json`) describing the resolved dependency graph. This is the default; pass `--pom` to generate `pom.xml` files instead',
},
pom: {
type: 'boolean',
description:
'Generate `pom.xml` manifest file(s) instead of the default Socket facts file (`.socket.facts.json`)',
'Generate `pom.xml` manifest file(s) instead of the default Socket facts file (`gradle.socket.facts.json`)',
},
includeConfigs: {
type: 'string',
Expand Down Expand Up @@ -78,9 +78,9 @@ const config: CliCommandConfig = {
Options
${getFlagListOutput(config.flags)}

By default, emits a single \`.socket.facts.json\` describing the resolved
dependency graph of the whole build, using gradle (preferably your local
\`gradlew\`). An unresolved dependency is a fatal error. You can pass
By default, emits a single \`gradle.socket.facts.json\` describing the
resolved dependency graph of the whole build, using gradle (preferably your
local \`gradlew\`). An unresolved dependency is a fatal error. You can pass
--include-configs / --exclude-configs (comma-separated glob patterns) to
control which configurations are resolved (e.g.
--include-configs=\`*CompileClasspath,*RuntimeClasspath\`), and
Expand Down
10 changes: 5 additions & 5 deletions src/commands/manifest/cmd-manifest-gradle.test.mts
Original file line number Diff line number Diff line change
Expand Up @@ -26,16 +26,16 @@ describe('socket manifest gradle', async () => {
--bin Location of the gradle binary to use, default: ./gradlew if present, else gradle on PATH
--exclude-configs When generating facts: comma-separated glob patterns; Gradle configurations matching any pattern are skipped (applied after --include-configs)
--exclude-paths List of glob patterns to exclude from manifest/facts generation. Patterns are anchored micromatch globs matched relative to CWD (\`--cwd\` if set): \`tests\` matches only \`<cwd>/tests\`; use \`**/tests\` to match at any depth. Negation patterns (\`!path\`) are not supported. Accepts a comma-separated value or multiple flags.
--facts Emit a Socket facts JSON file (\`.socket.facts.json\`) describing the resolved dependency graph. This is the default; pass \`--pom\` to generate \`pom.xml\` files instead
--facts Emit a Socket facts JSON file (\`gradle.socket.facts.json\`) describing the resolved dependency graph. This is the default; pass \`--pom\` to generate \`pom.xml\` files instead
--gradle-opts Additional options to pass on to ./gradlew, see \`./gradlew --help\`
--ignore-unresolved When generating facts: warn on unresolved dependencies instead of failing the run (unresolved deps are not emitted to the facts file)
--include-configs When generating facts: comma-separated glob patterns matched against Gradle configuration names (case-sensitive; \`*\`, \`?\`, and \`[...]\` wildcards). Only configurations matching at least one pattern are resolved. e.g. \`*CompileClasspath,*RuntimeClasspath\`. Default: every resolvable configuration
--pom Generate \`pom.xml\` manifest file(s) instead of the default Socket facts file (\`.socket.facts.json\`)
--pom Generate \`pom.xml\` manifest file(s) instead of the default Socket facts file (\`gradle.socket.facts.json\`)
--verbose Print debug messages

By default, emits a single \`.socket.facts.json\` describing the resolved
dependency graph of the whole build, using gradle (preferably your local
\`gradlew\`). An unresolved dependency is a fatal error. You can pass
By default, emits a single \`gradle.socket.facts.json\` describing the
resolved dependency graph of the whole build, using gradle (preferably your
local \`gradlew\`). An unresolved dependency is a fatal error. You can pass
--include-configs / --exclude-configs (comma-separated glob patterns) to
control which configurations are resolved (e.g.
--include-configs=\`*CompileClasspath,*RuntimeClasspath\`), and
Expand Down
10 changes: 5 additions & 5 deletions src/commands/manifest/cmd-manifest-kotlin.mts
Original file line number Diff line number Diff line change
Expand Up @@ -43,12 +43,12 @@ const config: CliCommandConfig = {
facts: {
type: 'boolean',
description:
'Emit a Socket facts JSON file (`.socket.facts.json`) describing the resolved dependency graph. This is the default; pass `--pom` to generate `pom.xml` files instead',
'Emit a Socket facts JSON file (`gradle.socket.facts.json`) describing the resolved dependency graph. This is the default; pass `--pom` to generate `pom.xml` files instead',
},
pom: {
type: 'boolean',
description:
'Generate `pom.xml` manifest file(s) instead of the default Socket facts file (`.socket.facts.json`)',
'Generate `pom.xml` manifest file(s) instead of the default Socket facts file (`gradle.socket.facts.json`)',
},
includeConfigs: {
type: 'string',
Expand Down Expand Up @@ -83,9 +83,9 @@ const config: CliCommandConfig = {
Options
${getFlagListOutput(config.flags)}

By default, emits a single \`.socket.facts.json\` describing the resolved
dependency graph of the whole build, using gradle (preferably your local
\`gradlew\`). An unresolved dependency is a fatal error. You can pass
By default, emits a single \`gradle.socket.facts.json\` describing the
resolved dependency graph of the whole build, using gradle (preferably your
local \`gradlew\`). An unresolved dependency is a fatal error. You can pass
--include-configs / --exclude-configs (comma-separated glob patterns) to
control which configurations are resolved (e.g.
--include-configs=\`*CompileClasspath,*RuntimeClasspath\`), and
Expand Down
10 changes: 5 additions & 5 deletions src/commands/manifest/cmd-manifest-kotlin.test.mts
Original file line number Diff line number Diff line change
Expand Up @@ -26,16 +26,16 @@ describe('socket manifest kotlin', async () => {
--bin Location of the gradle binary to use, default: ./gradlew if present, else gradle on PATH
--exclude-configs When generating facts: comma-separated glob patterns; Gradle configurations matching any pattern are skipped (applied after --include-configs)
--exclude-paths List of glob patterns to exclude from manifest/facts generation. Patterns are anchored micromatch globs matched relative to CWD (\`--cwd\` if set): \`tests\` matches only \`<cwd>/tests\`; use \`**/tests\` to match at any depth. Negation patterns (\`!path\`) are not supported. Accepts a comma-separated value or multiple flags.
--facts Emit a Socket facts JSON file (\`.socket.facts.json\`) describing the resolved dependency graph. This is the default; pass \`--pom\` to generate \`pom.xml\` files instead
--facts Emit a Socket facts JSON file (\`gradle.socket.facts.json\`) describing the resolved dependency graph. This is the default; pass \`--pom\` to generate \`pom.xml\` files instead
--gradle-opts Additional options to pass on to ./gradlew, see \`./gradlew --help\`
--ignore-unresolved When generating facts: warn on unresolved dependencies instead of failing the run (unresolved deps are not emitted to the facts file)
--include-configs When generating facts: comma-separated glob patterns matched against Gradle configuration names (case-sensitive; \`*\`, \`?\`, and \`[...]\` wildcards). Only configurations matching at least one pattern are resolved. e.g. \`*CompileClasspath,*RuntimeClasspath\`. Default: every resolvable configuration
--pom Generate \`pom.xml\` manifest file(s) instead of the default Socket facts file (\`.socket.facts.json\`)
--pom Generate \`pom.xml\` manifest file(s) instead of the default Socket facts file (\`gradle.socket.facts.json\`)
--verbose Print debug messages

By default, emits a single \`.socket.facts.json\` describing the resolved
dependency graph of the whole build, using gradle (preferably your local
\`gradlew\`). An unresolved dependency is a fatal error. You can pass
By default, emits a single \`gradle.socket.facts.json\` describing the
resolved dependency graph of the whole build, using gradle (preferably your
local \`gradlew\`). An unresolved dependency is a fatal error. You can pass
--include-configs / --exclude-configs (comma-separated glob patterns) to
control which configurations are resolved (e.g.
--include-configs=\`*CompileClasspath,*RuntimeClasspath\`), and
Expand Down
4 changes: 2 additions & 2 deletions src/commands/manifest/cmd-manifest-maven.mts
Original file line number Diff line number Diff line change
Expand Up @@ -67,8 +67,8 @@ const config: CliCommandConfig = {
Options
${getFlagListOutput(config.flags)}

Emits a single \`.socket.facts.json\` describing the resolved dependency
graph of your Maven project, using maven (\`mvn\` on PATH by default). It
Emits a single \`pom.xml.socket.facts.json\` (named after the POM Maven
runs on) describing the resolved dependency graph of your Maven project, using maven (\`mvn\` on PATH by default). It
reads dependency metadata only and never downloads artifacts; an unresolved
dependency is a fatal error. You can pass --include-configs /
--exclude-configs (comma-separated glob patterns) to control which Maven
Expand Down
4 changes: 2 additions & 2 deletions src/commands/manifest/cmd-manifest-maven.test.mts
Original file line number Diff line number Diff line change
Expand Up @@ -30,8 +30,8 @@ describe('socket manifest maven', async () => {
--maven-opts Additional options to pass on to maven, e.g. \`-P <profile> -s <settings.xml>\`
--verbose Print debug messages

Emits a single \`.socket.facts.json\` describing the resolved dependency
graph of your Maven project, using maven (\`mvn\` on PATH by default). It
Emits a single \`pom.xml.socket.facts.json\` (named after the POM Maven
runs on) describing the resolved dependency graph of your Maven project, using maven (\`mvn\` on PATH by default). It
reads dependency metadata only and never downloads artifacts; an unresolved
dependency is a fatal error. You can pass --include-configs /
--exclude-configs (comma-separated glob patterns) to control which Maven
Expand Down
14 changes: 7 additions & 7 deletions src/commands/manifest/cmd-manifest-scala.mts
Original file line number Diff line number Diff line change
Expand Up @@ -37,12 +37,12 @@ const config: CliCommandConfig = {
facts: {
type: 'boolean',
description:
'Emit a Socket facts JSON file (`.socket.facts.json`) describing the resolved dependency graph. This is the default; pass `--pom` to generate `pom.xml` files instead',
'Emit a Socket facts JSON file (`sbt.socket.facts.json`) describing the resolved dependency graph. This is the default; pass `--pom` to generate `pom.xml` files instead',
},
pom: {
type: 'boolean',
description:
'Generate `pom.xml` manifest file(s) instead of the default Socket facts file (`.socket.facts.json`)',
'Generate `pom.xml` manifest file(s) instead of the default Socket facts file (`sbt.socket.facts.json`)',
},
includeConfigs: {
type: 'string',
Expand All @@ -63,7 +63,7 @@ const config: CliCommandConfig = {
out: {
type: 'string',
description:
'Only with --pom: path of the output `pom.xml`, see also --stdout. Does not apply when generating Socket facts (always written to the project root as `.socket.facts.json`)',
'Only with --pom: path of the output `pom.xml`, see also --stdout. Does not apply when generating Socket facts (always written to the project root as `sbt.socket.facts.json`)',
},
stdout: {
type: 'boolean',
Expand All @@ -86,8 +86,8 @@ const config: CliCommandConfig = {
Options
${getFlagListOutput(config.flags)}

By default, emits a single \`.socket.facts.json\` describing the resolved
dependency graph of the whole build. It reads dependency metadata only and
By default, emits a single \`sbt.socket.facts.json\` describing the
resolved dependency graph of the whole build. It reads dependency metadata only and
never downloads artifacts; an unresolved dependency is a fatal error. You
can pass --include-configs / --exclude-configs (comma-separated glob
patterns) to control which sbt configurations are resolved (e.g.
Expand Down Expand Up @@ -304,7 +304,7 @@ async function run(
// would the file name be?

// --out / --stdout only affect the pom path. Socket facts are always written
// to the project root as `.socket.facts.json` so that `socket scan create`
// to the project root as `sbt.socket.facts.json` so that `socket scan create`
// picks them up, so reject these flags in facts mode rather than silently
// ignoring an explicitly-passed output location.
const wasValidInput = checkCommandInput(
Expand All @@ -322,7 +322,7 @@ async function run(
(cli.flags['out'] !== undefined || cli.flags['stdout'] !== undefined)
),
message:
'The `--out` and `--stdout` options only apply with `--pom`; Socket facts are always written to the project root as `.socket.facts.json`',
'The `--out` and `--stdout` options only apply with `--pom`; Socket facts are always written to the project root as `sbt.socket.facts.json`',
fail: 'remove --out/--stdout, or pass --pom',
},
)
Expand Down
10 changes: 5 additions & 5 deletions src/commands/manifest/cmd-manifest-scala.test.mts
Original file line number Diff line number Diff line change
Expand Up @@ -26,17 +26,17 @@ describe('socket manifest scala', async () => {
--bin Location of sbt binary to use
--exclude-configs When generating facts: comma-separated glob patterns; sbt configurations matching any pattern are skipped (applied after --include-configs)
--exclude-paths List of glob patterns to exclude from manifest/facts generation. Patterns are anchored micromatch globs matched relative to CWD (\`--cwd\` if set): \`tests\` matches only \`<cwd>/tests\`; use \`**/tests\` to match at any depth. Negation patterns (\`!path\`) are not supported. Accepts a comma-separated value or multiple flags.
--facts Emit a Socket facts JSON file (\`.socket.facts.json\`) describing the resolved dependency graph. This is the default; pass \`--pom\` to generate \`pom.xml\` files instead
--facts Emit a Socket facts JSON file (\`sbt.socket.facts.json\`) describing the resolved dependency graph. This is the default; pass \`--pom\` to generate \`pom.xml\` files instead
--ignore-unresolved When generating facts: warn on unresolved dependencies instead of failing the run (unresolved deps are not emitted to the facts file)
--include-configs When generating facts: comma-separated glob patterns matched against sbt configuration names (case-sensitive; \`*\`, \`?\`, and \`[...]\` wildcards). Only configurations matching at least one pattern are resolved. e.g. \`compile,test\`. Default: compile,optional,provided,runtime,test
--out Only with --pom: path of the output \`pom.xml\`, see also --stdout. Does not apply when generating Socket facts (always written to the project root as \`.socket.facts.json\`)
--pom Generate \`pom.xml\` manifest file(s) instead of the default Socket facts file (\`.socket.facts.json\`)
--out Only with --pom: path of the output \`pom.xml\`, see also --stdout. Does not apply when generating Socket facts (always written to the project root as \`sbt.socket.facts.json\`)
--pom Generate \`pom.xml\` manifest file(s) instead of the default Socket facts file (\`sbt.socket.facts.json\`)
--sbt-opts Additional options to pass on to sbt, as per \`sbt --help\`
--stdout Only with --pom: print the resulting \`pom.xml\` to stdout (supersedes --out). Does not apply when generating Socket facts
--verbose Print debug messages

By default, emits a single \`.socket.facts.json\` describing the resolved
dependency graph of the whole build. It reads dependency metadata only and
By default, emits a single \`sbt.socket.facts.json\` describing the
resolved dependency graph of the whole build. It reads dependency metadata only and
never downloads artifacts; an unresolved dependency is a fatal error. You
can pass --include-configs / --exclude-configs (comma-separated glob
patterns) to control which sbt configurations are resolved (e.g.
Expand Down
3 changes: 2 additions & 1 deletion src/commands/manifest/convert-gradle-to-facts.mts
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@ import { runManifestFacts } from './run-manifest-facts.mts'

import type { SidecarAccumulator } from './scripts/sidecar.mts'

// Generates `.socket.facts.json` for a Gradle project via the bundled init script.
// Generates `gradle.socket.facts.json` for a Gradle project via the bundled
// init script.
export async function convertGradleToFacts({
bin,
cwd,
Expand Down
3 changes: 2 additions & 1 deletion src/commands/manifest/convert-maven-to-facts.mts
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@ import { runManifestFacts } from './run-manifest-facts.mts'

import type { SidecarAccumulator } from './scripts/sidecar.mts'

// Generates `.socket.facts.json` for a Maven project via the bundled extension.
// Generates `pom.xml.socket.facts.json` (named after the POM Maven runs on)
// for a Maven project via the bundled extension.
export async function convertMavenToFacts({
bin,
cwd,
Expand Down
2 changes: 1 addition & 1 deletion src/commands/manifest/convert-sbt-to-facts.mts
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ import { runManifestFacts } from './run-manifest-facts.mts'

import type { SidecarAccumulator } from './scripts/sidecar.mts'

// Generates `.socket.facts.json` for an sbt project via the bundled sbt plugin.
// Generates `sbt.socket.facts.json` for an sbt project via the bundled sbt plugin.
// sbt 0.13/early 1.x can't run on modern JDKs — pass a compatible JDK via
// `--sbt-opts "--java-home <path>"` or `JAVA_HOME`.
export async function convertSbtToFacts({
Expand Down
Loading
Loading