Skip to content

docs(contributing): say that CodeQL and Socket are advisory, not gates - #12

Merged
TMHSDigital merged 1 commit into
mainfrom
docs/advisory-checks-do-not-gate
Sep 22, 2026
Merged

TMHSDigital merged 1 commit into
mainfrom
docs/advisory-checks-do-not-gate

Conversation

@TMHSDigital

Copy link
Copy Markdown
Owner

Neither CodeQL nor Socket Security is a required check. That was true by omission, so nobody reading CONTRIBUTING would know it.

Adds one paragraph under the pull request flow: the four CI jobs gate a merge, the advisory checks deliberately do not, and a Socket alert on a dependency change is the one worth stopping for because it is the case that tooling is genuinely good at. Says plainly that clicking past it silently is the failure mode, and so is panicking at a transitive dependency's changelog.

Docs only.

Neither is a required check, which was true by omission and therefore not
communicated. The first contributor to see a Socket warning would either panic
or click past it, and neither is the intent.

States which checks gate a merge (the four CI jobs), that the advisory ones are
deliberately not gates because a supply-chain advisory is a human judgement
call, and what to actually do with one: a package that has started running
install scripts or reaching the network is a real signal even with no CVE, and
the conclusion belongs in the pull request.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
@TMHSDigital
TMHSDigital merged commit e4054c1 into main Sep 22, 2026
9 checks passed
@TMHSDigital
TMHSDigital deleted the docs/advisory-checks-do-not-gate branch September 22, 2026 02:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant