Skip to content

feat(scan): recognise any *.socket.facts.json - #1589

Merged
Jeppe Fredsgaard Blaabjerg (jfblaa) merged 2 commits into
v1.xfrom
jfblaa/facts-any-name
Oct 8, 2026
Merged

Jeppe Fredsgaard Blaabjerg (jfblaa) merged 2 commits into
v1.xfrom
jfblaa/facts-any-name

Conversation

@jfblaa

@jfblaa Jeppe Fredsgaard Blaabjerg (jfblaa) commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

LLM Description written by Claude Code:claude-opus-5-5

First of a stack splitting #1587 into reviewable steps. JVM facts producers are moving to one facts file per build, named after it (pom.xml.socket.facts.json, ...). This PR makes scan and fix recognise those names. Today's .socket.facts.json behaves as before.

  • Any *.socket.facts.json counts as a Socket facts file, matching depscan: in socket fix's leftover-facts check, the --auto-manifest suggestion, and when the reachability report replaces facts inputs in the scan.
  • Named facts files upload uncompressed, since depscan only decompresses the bare .socket.facts.json.br.

No Coana dependency.

Stack: this → #1590 → #1591 → #1587

🤖 Generated with Claude Code

…eports out of input

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Bare facts excluded from reachability input
    • isReachabilityReportPath now treats only the scan-directory .socket.facts.json and this run's output path as leftover Coana reports, so producer facts at nested build roots stay in the reachability upload and pregenerated SBOM inputs.

Create PR

Or push these changes by commenting:

@cursor push 317ad369d4
Preview (317ad369d4)
diff --git a/src/commands/scan/handle-create-new-scan.test.mts b/src/commands/scan/handle-create-new-scan.test.mts
--- a/src/commands/scan/handle-create-new-scan.test.mts
+++ b/src/commands/scan/handle-create-new-scan.test.mts
@@ -316,7 +316,11 @@
     })
     await handleCreateNewScan(config)
     expect(mockFetchCreateOrgFullScan).toHaveBeenCalledWith(
-      ['/repo/pom.xml.socket.facts.json', '.socket.facts.json'],
+      [
+        '/repo/pom.xml.socket.facts.json',
+        '/repo/service/.socket.facts.json',
+        '.socket.facts.json',
+      ],
       'fakeOrg',
       expect.anything(),
       expect.anything(),

diff --git a/src/commands/scan/perform-reachability-analysis.test.mts b/src/commands/scan/perform-reachability-analysis.test.mts
--- a/src/commands/scan/perform-reachability-analysis.test.mts
+++ b/src/commands/scan/perform-reachability-analysis.test.mts
@@ -247,6 +247,7 @@
       'package.json',
       'pom.xml.socket.facts.json',
       'gradle.socket.facts.json',
+      'nested/.socket.facts.json',
     ])
   })
 

diff --git a/src/utils/coana.mts b/src/utils/coana.mts
--- a/src/utils/coana.mts
+++ b/src/utils/coana.mts
@@ -131,8 +131,9 @@
 }
 
 // A Coana reachability report, never input to a new analysis: the bare
-// `.socket.facts.json` (Coana's default name; producers name theirs after the
-// build) or the path this run tells Coana to write to.
+// `.socket.facts.json` at the scan directory, or the path this run tells
+// Coana to write to. Producers still write that basename at each build root;
+// those files stay input.
 export function isReachabilityReportPath(
   filepath: string,
   options: { cwd: string; outputPath: string },
@@ -141,9 +142,16 @@
     cwd: string
     outputPath: string
   }
+  const resolvedCwd = path.resolve(cwd)
+  const resolvedFile = path.resolve(resolvedCwd, filepath)
+  const resolvedOutput = path.resolve(resolvedCwd, outputPath)
+  if (resolvedFile === resolvedOutput) {
+    return true
+  }
+  const relativeToCwd = path.relative(resolvedCwd, resolvedFile)
   return (
-    path.basename(filepath).toLowerCase() === DOT_SOCKET_DOT_FACTS_JSON ||
-    path.resolve(cwd, filepath) === path.resolve(cwd, outputPath)
+    path.basename(relativeToCwd).toLowerCase() === DOT_SOCKET_DOT_FACTS_JSON &&
+    path.dirname(relativeToCwd) === '.'
   )
 }
 

diff --git a/src/utils/coana.test.mts b/src/utils/coana.test.mts
--- a/src/utils/coana.test.mts
+++ b/src/utils/coana.test.mts
@@ -78,7 +78,8 @@
     const options = { cwd: '/repo', outputPath: 'out/report.json' }
     it.each([
       '.socket.facts.json',
-      'a/.SOCKET.FACTS.JSON',
+      '/repo/.socket.facts.json',
+      '.SOCKET.FACTS.JSON',
       '/repo/out/report.json',
       'out/report.json',
     ])('matches %s', p => {
@@ -87,6 +88,9 @@
     it.each([
       'pom.xml.socket.facts.json',
       'gradle.socket.facts.json',
+      'a/.socket.facts.json',
+      'a/.SOCKET.FACTS.JSON',
+      'service-a/.socket.facts.json',
       'report.json',
     ])('rejects %s', p => {
       expect(isReachabilityReportPath(p, options)).toBe(false)

You can send follow-ups to the cloud agent here.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 7594c03. Configure here.

Comment thread src/utils/coana.mts Outdated
@BarrensZeppelin
Oskar Haarklou Veileborg (BarrensZeppelin) added this pull request to stack #1592 October 8, 2026 10:38
Producers still write that name, so leaving it out of the reachability
upload dropped their dependency graphs. Excluding earlier reports moves to
the change that renames producer output.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jfblaa Jeppe Fredsgaard Blaabjerg (jfblaa) changed the title feat(scan): recognise any *.socket.facts.json and keep reachability reports out of input feat(scan): recognise any *.socket.facts.json Oct 8, 2026

@mtorp Martin Torp (mtorp) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM ✅

@jfblaa
Jeppe Fredsgaard Blaabjerg (jfblaa) merged commit 040b7aa into v1.x Oct 8, 2026
6 checks passed
@jfblaa
Jeppe Fredsgaard Blaabjerg (jfblaa) deleted the jfblaa/facts-any-name branch October 8, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants