Conversation
`scan_all` is the documented escape hatch when a `changed_files` scope cannot be resolved, but it was reachable only from the GitHub Action input, `INPUT_SCAN_ALL`, a `--config` JSON key or dashboard config. The failure message told operators to "set scan_all" without saying how, and on the CLI there was no way to follow that instruction at all — every neighbouring scope setting (`--changed-files`, `--scan-files`, `--workspace`) already had a flag. Add the paired `--scan-all` / `--no-scan-all` form rather than a plain `store_true`: the setting defaults to false but can already be on from the environment, a config file or the dashboard, and a `store_true` flag could never turn that back off. Absent, the flag parses to `None`, so it never overwrites one of those sources with an implicit false. The unresolvable-scope error now names the concrete remediation for each interface instead of just the config key. Refs CE-455 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Rewrite the new comments to state present-tense invariants rather than the shape of the change: the declaration-site comment keeps only the rationale for the paired flag form, the application site keeps only what `None` must not do, and the test class docstring describes the constraint the flag satisfies instead of what was missing before it. Also use the repo's dominant American spelling in the --help string and the docs that quote it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit ad685cc. Configure here.
--scan-all and --no-scan-all CLI flags
Phil Gran (philgran)
approved these changes
Sep 15, 2026
lelia
added a commit
that referenced
this pull request
Sep 15, 2026
Release prep for 3.3.0, bundling #114 and #115. #115 adds the `--scan-all` / `--no-scan-all` CLI flags, so this is a minor bump rather than a patch. Bumps pyproject.toml, socket_basics/version.py, socket_basics/__init__.py, action.yml and uv.lock to 3.3.0, synchronizes 83 current-release references across README.md and docs/**, and stamps [Unreleased] as [3.3.0] - 2026-09-15. Also pins the Socket Python CLI to 2.9.0 in Dockerfile.heavy and app_tests/Dockerfile, ahead of that release publishing to PyPI.
lelia
added a commit
that referenced
this pull request
Sep 15, 2026
Release prep for 3.3.0, bundling #114 and #115. #115 adds the `--scan-all` / `--no-scan-all` CLI flags, so this is a minor bump rather than a patch. Bumps pyproject.toml, socket_basics/version.py, socket_basics/__init__.py, action.yml and uv.lock to 3.3.0, synchronizes 83 current-release references across README.md and docs/**, and stamps [Unreleased] as [3.3.0] - 2026-09-15. Also pins the Socket Python CLI to 2.9.0 in Dockerfile.heavy and app_tests/Dockerfile, ahead of that release publishing to PyPI.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
scan_allis the documented escape hatch for achanged_filesscope that cannot be resolved, but it was reachable only from the GitHub Action input,INPUT_SCAN_ALL, a--configJSON key, or dashboard configuration. There was no--scan-allflag, so the error raised on an unresolvable scope recommended a remediation the CLI could not perform:#111 was an explicit CLI/action-input parity pass and
scan_allwas the one setting it missed; every neighboring scope setting (--changed-files,--scan-files,--workspace) already had a flag. This adds it and makes the error name a concrete remediation for each interface.Changes
socket_basics/core/config.py--scan-all/--no-scan-all, wired to the samescan_allconfig key as every other interface.BooleanOptionalActionform rather than the plainstore_truethis repo uses for its other default-false booleans.scan_alldefaults to false but can already be on fromINPUT_SCAN_ALL, a--configfile or dashboard config, andstore_trueoffers no way to turn that back off. Absent, the flag parses toNone, so it only speaks when the operator used it and never overwrites one of those sources with an implicit false.--scan-all, thescan_allaction input,INPUT_SCAN_ALL, or a--configJSON / dashboard key — instead of only naming the config key.Documentation
docs/parameters.md: the Name Mapping row forscan_allshowed—in the CLI column, which was accurate before this change; it now lists both flags. Adds a--scan-all,--no-scan-allentry under Core Options, and updates the diff-only scoping prose to give the CLI spelling alongside the others.docs/github-action.md: the scope troubleshooting table, the "Where the setting can come from" paragraph, and the scan-scope input list all cross-reference the flag.CHANGELOG.md— Added and Changed entries under[Unreleased]. No version bump; that stays with the release-prep PR.Testing
391 passedlocally, including a newTestScanAllCliFlagclass intests/test_changed_files_scope.pycovering flag parsing (--scan-all→True,--no-scan-all→False, absent →None), the fail-open opt-in, the fail-closed default,--no-scan-alloverridingINPUT_SCAN_ALL=true, omission deferring to the environment value, and the error naming every interface.Also verified end to end against the reproduction in the ticket, on a non-git workspace with a PEM key and a Slack webhook URL:
--changed-files auto--changed-files auto --scan-allINPUT_SCAN_ALL=true ... --no-scan-allINPUT_SCAN_ALL=true ...(no flag)The widened runs stop at TruffleHog's missing-binary error on this machine, which is the documented fail-closed behavior from 3.2.0 rather than a regression; the scope resolution itself is what these exercise.
scripts/check_release_docs.py --checkpasses.Fixes CE-455
Note
Low Risk
Small CLI/config parity change with explicit precedence rules and tests; no change to scan logic when scope resolves successfully.
Overview
Adds
--scan-alland--no-scan-allso the CLI matches the existingscan_allaction input,INPUT_SCAN_ALL, and JSON/dashboard settings. When--changed-filescannot be resolved, operators can opt into a full-workspace fallback from the command line instead of only via non-CLI config.The flags use
BooleanOptionalActionwith defaultNone: omitting both leaves env/JSON/dashboard values alone;--no-scan-allforces fail-closed for one run even whenINPUT_SCAN_ALLis set. The unresolvable-scopeSystemExitmessage now lists every way to enable the fallback (CLI, action input, env, config).Docs (
CHANGELOG,parameters.md,github-action.md) andTestScanAllCliFlagcover parsing, precedence, fallback behavior, and the updated error text.Reviewed by Cursor Bugbot for commit ad685cc. Configure here.