From 8efb72b9874f47cefc45c7d6991b6f87de42251e Mon Sep 17 00:00:00 2001 From: TMHSDigital <154358121+TMHSDigital@users.noreply.github.com> Date: Mon, 21 Sep 2026 21:54:00 -0400 Subject: [PATCH] docs(contributing): say that CodeQL and Socket are advisory, not gates Neither is a required check, which was true by omission and therefore not communicated. The first contributor to see a Socket warning would either panic or click past it, and neither is the intent. States which checks gate a merge (the four CI jobs), that the advisory ones are deliberately not gates because a supply-chain advisory is a human judgement call, and what to actually do with one: a package that has started running install scripts or reaching the network is a real signal even with no CVE, and the conclusion belongs in the pull request. Co-Authored-By: Claude Opus 5 (1M context) --- CONTRIBUTING.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 6460173..5344362 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -84,6 +84,20 @@ The flow: required checks. 6. **Squash on merge.** The branch is deleted automatically afterwards. +**Some checks are advisory and do not gate a merge.** CodeQL and Socket +Security both report on pull requests, and neither is a required check. The +four CI jobs are the gate. This is deliberate, not an oversight: a +supply-chain advisory is a judgement call that a human should make, and a +scanner that can block a merge on a false positive ends up being routed around +rather than read. + +So read them. A Socket alert on a dependency change is the one worth stopping +for, because it is the case the tooling is actually good at: a package that has +started running install scripts or reaching the network is a real signal even +with no CVE attached. Say in the pull request what you concluded. Clicking past +it silently is the failure mode, and so is panicking at a report that turns out +to be a transitive dependency's changelog. + The maintainer can bypass the ruleset, and does so for typos and documentation rather than opening a pull request against themselves. That bypass is a convenience for trivial changes, not a way around CI for real ones.