docs(dependencies): clarify socket.yml is registry-side scan, not CI gate (#12664)

* docs(dependencies): clarify socket.yml is registry-side scan, not CI gate

* docs(dependencies): add changelog fragment for socket.yml scope note

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

---------

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
This commit is contained in:
Juri
2026-09-18 17:22:09 +02:00
committed by GitHub
parent 6e74739607
commit db5ae3c33d
4 changed files with 13 additions and 0 deletions

View File

@@ -5,6 +5,8 @@ description: "Maintainer attestation for the AI-detected potential-malware findi
# Socket.dev / supply-chain finding attestation
> **Scope note:** `socket.yml` configures Socket.dev's registry-side post-publish scan of the npm artifact (ignore-paths for non-shipped content such as `tests/`, `docs/`, and build reports). It does not wire a CI/PR merge gate — no workflow in `.github/workflows`, no `package.json` script, and no `Makefile` target invokes Socket.dev.
This document is the maintainer-authored attestation for the six
`AI-detected potential malware` findings raised against `omniroute@3.8.5` and
the mitigations applied in `omniroute@3.8.6`. It exists so: