Skip to content

chore(wheelhouse): re-cascade to template@d60c6f3 and repair the build - #20

Merged
Julian Gruber (juliangruber) merged 10 commits into
mainfrom
chore/cascade-template-d60c6f3
Sep 30, 2026
Merged

Julian Gruber (juliangruber) merged 10 commits into
mainfrom
chore/cascade-template-d60c6f3

Conversation

@juliangruber

@juliangruber Julian Gruber (juliangruber) commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Why

All CI on this repo has failed since Sept 17 because the repo fell out of sync with socket-wheelhouse. Setup dies before any repo code runs, and build, test, type and the pre-push hook fail from a clean clone. Re-cascading brings the committed side back to the pack.

What

The chore(wheelhouse) ones are the cascade's own commits, made by socket-wheelhouse/scripts/repo/commit-cascade/run.mts --target . --fix; the other eight are repo-owned edits without which either CI or the pre-push hook still fails.

Why two cascade passes: the tool commits only the paths it fixed in the current run, and the lockfile reconcile depends on the bumped pnpm-workspace.yaml being committed first. A member this far behind the template needs the cascade run to a fixed point, and each pass is one commit by design.

# Commit What
1 6659922 docs: move the engineering rules to AGENTS.md Hand-made to work around two wheelhouse bugs.
2 691a359 chore(wheelhouse): cascade template@d60c6f3 Main cascade pass.
3 a81798c chore(wheelhouse): cascade template@d60c6f3 Second pass: lockfile reconcile against the bumped catalog (pnpm-lock.yaml, pnpm-workspace.yaml), which only resolves once the first pass is committed.
4 e21ba26 fix(build): import runMain from its new fleet path Repo-owned scripts/repo/build.mts and test/repo/unit/build.test.mts imported scripts/fleet/process/run-main.mts, which the pack no longer ships. Without this pnpm run build and pnpm test fail (CI Test job), pnpm run type fails (CI Check job), and the pre-push type gate blocks every push.
5 649ce21 docs: seed CONTRIBUTING.md from the fleet preset Placed by the cascade (preset_missing) but not committed by it, presets being repo-owned after seeding. Left untracked it fails working-tree-is-clean in pnpm run check and the next cascade re-seeds it.
6 4ef0fc9 style: format the CI workflows with the pinned oxfmt oxfmt 0.70 (from the catalog bump) rejects the double-quoted labels in ci-gates.yml/ci-fix.yml. The pre-push fast lint/format gate blocked the push on exactly these two files.
7 3d6793d ci: drop the npm publish workflow this repo never uses The fleet's workflow-name lint (wheelhouse 7deb481) rejects publish-npm.yml's 📦 Publish npm title and blocked the push. The file is the fleet's conditional npm-publish workflow; this package is private: true and ships only as a GitHub Action, so the cascade neither refreshes it nor declares a channel, and the cascade's own report says to remove it or declare a channel. Renaming it trips the reserved publish: npm task-name contract instead.
8 43e2487 test(firewall): annotate the timers mock for the new assertion lint oxlint 1.85 (from the catalog bump) enables no-unsafe-type-assertion, which flags the as T in the setTimeout mock from #17 and blocked the push at the pre-push lint gate; the CI Check job runs the same lint. Allowed per call site with a reason, since the assertion mirrors node's own setTimeout(delay, value) contract.
9 5a60c4e ci: adopt the current preset CI workflows ci-gates.yml and ci-fix.yml are preset-tier (seeded once, then repo-owned), so the cascade does not refresh them. Current preset: pinned runner images, cache-mode: none on repair, CI-tier pnpm run ci:gates stages instead of developer-tier check --all.
10 1f1fd50 docs: retitle AGENTS.md and drop the template placeholder The pure rename in commit 1 kept CLAUDE.md's heading and the template's placeholder repo section, which held no repository rules. Retitled and trimmed so the file matches what the cascade's rule-file fixer produces; without it the file is literally headed # CLAUDE.md.

dist/ is byte-identical to main; this PR changes no action behaviour.

Why not squashed: the push hook wants one commit per PR branch, but squashing re-runs the pre-commit canonical-fork scanner over cascade output, which it can only verify inside a wheelhouse checkout. Prior cascades (7e247cd, 18ac884) were pushed straight to main and never met that rule.

Verification

Local (pnpm 12.7.0 from the fleet's pinned release, pack d60c6f3 hydrated): type ✔, build ✔ (dist unchanged), test ✔ 18 files / 192 tests, lint --all ✔. Pushed with hooks enabled.

CI on 7b8a3e3, the previous head, whose tree differs from this one only in the cascade's catalog picks a day later (fallow 3.28.0, TypeScript dev 20260922) and the lockfile that follows them: Check distribution ✔, Test on ubuntu-26.04 / macos-26 / windows-2025 ✔, CodeQL ✔, Bugbot ✔. Check ✖ on one finding, commits-are-signed, which is a false negative for SSH signers in CI (see comment below); not a required status.

After this

#19 and #18 rebase onto this so their CI can run; #18 additionally onto #19 for the v1.15.3 checksum table.

🤖 Generated with Claude Code

@socket-security-staging

socket-security-staging Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Low adoption: npm @ultrathink/acorn.rs.wasm

Location: Package overview

From: package.json → npm/@ultrathink/acorn.rs.wasm@0.2.0

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@ultrathink/acorn.rs.wasm@0.2.0. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm typescript is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/typescript@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/typescript@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-aix-ppc64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-aix-ppc64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-aix-ppc64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-darwin-arm64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-darwin-arm64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-darwin-arm64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-darwin-x64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-darwin-x64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-darwin-x64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-freebsd-arm64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-freebsd-arm64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-freebsd-arm64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-freebsd-x64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-freebsd-x64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-freebsd-x64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-linux-arm is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-linux-arm@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-linux-arm@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-linux-arm64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-linux-arm64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-linux-arm64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-linux-loong64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-linux-loong64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-linux-loong64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-linux-mips64el is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-linux-mips64el@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-linux-mips64el@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-linux-ppc64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-linux-ppc64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-linux-ppc64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-linux-riscv64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-linux-riscv64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-linux-riscv64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-linux-s390x is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-linux-s390x@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-linux-s390x@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-linux-x64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-linux-x64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-linux-x64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-netbsd-arm64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-netbsd-arm64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-netbsd-arm64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-netbsd-x64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-netbsd-x64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-netbsd-x64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-openbsd-arm64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-openbsd-arm64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-openbsd-arm64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-openbsd-x64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-openbsd-x64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-openbsd-x64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-sunos-x64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-sunos-x64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-sunos-x64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-win32-arm64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-win32-arm64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-win32-arm64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Publisher changed: npm @typescript/typescript-win32-x64 is now published by microsoft1es

Author: microsoft1es

From: pnpm-lock.yaml → npm/fallow@3.28.0 → npm/@typescript/typescript-win32-x64@7.0.2

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@typescript/typescript-win32-x64@7.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@juliangruber

This comment was marked as outdated.

The fleet's rule-file authority is AGENTS.md; the cascade generates
CLAUDE.md as an ignored pointer at it. A pure rename, content untouched:
the cascade regenerates the fleet block in its own commit.

This should be the cascade's rule-file migration, but two wheelhouse
bugs stop it from landing on its own: the claude_md_fleet_drift fixer
writes AGENTS.md and the migration then refuses the two-authored-files
state it just created, and a staged CLAUDE.md deletion sends the
cascade's commit pass through a temp-index path that fails with no
error text. Renaming first, as a repo-owned commit, puts the cascade
back on its normal path.
Auto-applied by socket-wheelhouse commit-cascade into action.
74 file(s) touched:
  - .claude/settings.json
  - .config/fleet/oxlintrc.json
  - .git-hooks/_shared/canonical/source.mts
  - .git-hooks/_shared/push-commit-messages.mts
  - .git-hooks/_shared/push-durable-ref.mts
  - .git-hooks/_shared/push-file-scan.mts
  - .git-hooks/_shared/push-range.mts
  - .git-hooks/_shared/push-release-tags.mts
  - .git-hooks/_shared/push-repo-gates.mts
  - .git-hooks/_shared/push-signatures.mts
  - .git-hooks/_shared/push-squash-history.mts
  - .git-hooks/_shared/run-step.sh
  - .git-hooks/_shared/scan-core.mts
  - .git-hooks/fleet/pre-push.mts
  - .gitattributes
  - .github/actions/fleet/_shared/codeql-languages.d.mts
  - .github/actions/fleet/_shared/codeql-languages.mjs
  - .github/actions/fleet/_shared/install-tool.mjs
  - .github/actions/fleet/_shared/platform-key.mjs
  - .github/actions/fleet/_shared/platform.mjs
  ... and 54 more
Auto-applied by socket-wheelhouse commit-cascade into action.
1 file(s) touched:
  - pnpm-workspace.yaml
The fleet pack moved scripts/fleet/process/run-main.mts to
scripts/fleet/process/main/run.mts. build.mts and its test still pointed
at the old path, which is why `pnpm run build`, `pnpm test` and the
pre-push type check failed from a clean clone.
publish-npm.yml is the fleet's conditional workflow for repos that
publish to the npm registry. This package is private and ships only as
a GitHub Action, so the cascade neither refreshes the copy nor declares
a channel for it, and the stale copy fails the fleet's workflow-name
lint on every push. The cascade's own guidance is to remove it.
oxlint 1.85 (from the catalog bump) enables
typescript/no-unsafe-type-assertion, which flags the `as T` in the
setTimeout mock. The assertion mirrors node's own contract, so it is
allowed per call site with a reason rather than rewritten.
ci-gates.yml and ci-fix.yml are preset-tier (seeded once, then
repo-owned), so the cascade does not refresh them. The copies here were
the preset as of the August onboarding. The current preset pins hosted
runners to explicit OS versions, sets cache-mode: none on the repair
job, and runs the CI-tier `pnpm run ci:gates` stages instead of the
developer-tier `check --all`, which is what the fleet's own check job
now expects. No local customisation was present in either file.
The pure rename kept CLAUDE.md's heading and the template's placeholder
repo section. Title the file for what it is and remove the placeholder,
which held no repository rules. Content now matches what the cascade's
rule-file fixer produces.
@juliangruber
Julian Gruber (juliangruber) merged commit aeee726 into main Sep 30, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant