Files
agentic-dev/docs/work/2026-05-14-ci-security-and-supply-chain/02-socket-integration/_story.md
Danijel Martinek 90fc2853f2 feat(work): add ISO timestamps + auto-bump on staged work-doc changes
- New scripts/work/bump-updated-timestamps.mjs stamps the `updated:`
  frontmatter field to the current ISO 8601 UTC timestamp on every
  staged docs/work/**/*.md file. Idempotent; adds the field after
  `created:` if missing.
- .husky/pre-commit invokes the bump script as step 2 (before
  rebuild-state) so _state.json sees the fresh timestamp.
- Backfill all existing work docs (4 PRDs + 3 epics + 21 stories):
    * created: promoted from \`YYYY-MM-DD\` -> ISO timestamp using
      git log --diff-filter=A on each file (first-commit date for
      stories that had no \`created:\` line, midnight UTC for PRDs
      and epics that had date-only created).
    * updated: added from \`git log -1 --format=%aI\` on each file
      (last-commit timestamp); will be re-stamped to "now" by the
      pre-commit hook on this commit.

Stories that had no \`created:\` line now get one.
2026-05-14 21:10:34 +02:00

3.3 KiB

id, epic, title, type, status, feature, depends-on, blocks, created, updated
id epic title type status feature depends-on blocks created updated
02-socket-integration 2026-05-14-ci-security-and-supply-chain Socket integration (skill + CI) technical-story done tooling
01-trace-schema-extensions
08-reviewer-prompt-update
2026-05-14T18:59:12+02:00 2026-05-14T19:10:35.370Z

Goal

Wire Socket.dev into two enforcement layers: (1) the evaluate-library skill gains Filter 9 (supply-chain behavior) using socket-cli, and (2) ci.yml gains a socket-cli scan step that fails on critical severity findings.

Why

CVE databases are lagging indicators — event-stream, ua-parser-js, and tj-actions/changed-files all shipped malware before any CVE existed. Socket detects behavioral signals (new network calls, new post-install scripts, maintainer-account changes) in real time. Placing it as the 9th filter in evaluate-library + as a CI gate closes the behavior-compromise surface that CVE scanning misses.

External dependency: library-evaluation epic story 04 (evaluate-library skill) must be complete — the skill's SKILL.md must exist and have the 8-filter structure. That epic is marked done.

Done when

  • .claude/skills/evaluate-library/SKILL.md has a "Filter 9 — Supply-chain behavior (Socket)" section. The skill's fail-fast logic positions Socket as expensive (network call), running it after the cheap structural filters. The section documents the socket-cli verification command and the JSON output fields used to classify clean / flagged / <finding-summary>. The trace's socket-risk field in filter-results is set from this output.
  • .socket.json exists at repo root: { "issueRules": { "critical": "error", "high": "warn", "medium": "ignore", "low": "ignore" } }.
  • ci.yml's validate job has a step that runs socket-cli scan against the lockfile, filtered to PRs that touch package.json or pnpm-lock.yaml (via paths: condition). The step exits non-zero on any critical finding.
  • docs/guides/ci-security.md Socket App install instructions are deferred to Story 09 (the human guide). This story ships only the machine-enforced layers.
  • pnpm typecheck && pnpm lint && pnpm test && pnpm conformance && pnpm fallow:audit && pnpm coverage:diff all pass.

In scope

  • .claude/skills/evaluate-library/SKILL.md — Filter 9 section addition.
  • .socket.json — repo-root config file.
  • .github/workflows/ci.yml — one new step in the validate job (with paths: filter).

Out of scope

  • Paid Socket Team plan or server-side PR-block enforcement — explicitly out of PRD scope.
  • Socket GitHub App install — consumer-facing instructions live in Story 09's guide.
  • Backfilling existing traces with socket-risk — Story 05 (revalidation cron handles this).

Tasks

  • Add .socket.json at repo root and extend .claude/skills/evaluate-library/SKILL.md with a "Filter 9 — Supply-chain behavior (Socket)" section: position Socket after cheap filters, document socket-cli as the verification command, specify how clean/flagged/<finding-summary> maps to the trace's socket-risk field; one commit, all gates pass.
  • Add a socket-cli scan step to ci.yml's validate job, scoped to PRs touching package.json or pnpm-lock.yaml via a paths: condition; step exits non-zero on any critical finding; one commit, all gates pass.