Skip to content

feat(config): add --scan-all and --no-scan-all CLI flags - #115

Merged
lelia merged 3 commits into
mainfrom
leliahui/ce-455-socket-basics-scan_all-has-no-cli-flag-so-the-error-messages
Sep 15, 2026
Merged

lelia merged 3 commits into
mainfrom
leliahui/ce-455-socket-basics-scan_all-has-no-cli-flag-so-the-error-messages

Conversation

@lelia

@lelia lelia commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

scan_all is the documented escape hatch for a changed_files scope that cannot be resolved, but it was reachable only from the GitHub Action input, INPUT_SCAN_ALL, a --config JSON key, or dashboard configuration. There was no --scan-all flag, so the error raised on an unresolvable scope recommended a remediation the CLI could not perform:

changed_files: the requested scope could not be resolved, so the scan would either report a
green run having scanned nothing or silently widen to the whole repository. See the warnings
above for the underlying git error. Fix the git problem, or set scan_all to widen to a
full-repo scan when the scope cannot be resolved.

#111 was an explicit CLI/action-input parity pass and scan_all was the one setting it missed; every neighboring scope setting (--changed-files, --scan-files, --workspace) already had a flag. This adds it and makes the error name a concrete remediation for each interface.

Changes

socket_basics/core/config.py

  • Adds --scan-all / --no-scan-all, wired to the same scan_all config key as every other interface.
  • Uses argparse's paired BooleanOptionalAction form rather than the plain store_true this repo uses for its other default-false booleans. scan_all defaults to false but can already be on from INPUT_SCAN_ALL, a --config file or dashboard config, and store_true offers no way to turn that back off. Absent, the flag parses to None, so it only speaks when the operator used it and never overwrites one of those sources with an implicit false.
  • The unresolvable-scope error now names the remediation per interface — --scan-all, the scan_all action input, INPUT_SCAN_ALL, or a --config JSON / dashboard key — instead of only naming the config key.

Documentation

  • docs/parameters.md: the Name Mapping row for scan_all showed — in the CLI column, which was accurate before this change; it now lists both flags. Adds a --scan-all, --no-scan-all entry under Core Options, and updates the diff-only scoping prose to give the CLI spelling alongside the others.
  • docs/github-action.md: the scope troubleshooting table, the "Where the setting can come from" paragraph, and the scan-scope input list all cross-reference the flag.

CHANGELOG.md — Added and Changed entries under [Unreleased]. No version bump; that stays with the release-prep PR.

Testing

391 passed locally, including a new TestScanAllCliFlag class in tests/test_changed_files_scope.py covering flag parsing (--scan-all → True, --no-scan-all → False, absent → None), the fail-open opt-in, the fail-closed default, --no-scan-all overriding INPUT_SCAN_ALL=true, omission deferring to the environment value, and the error naming every interface.

Also verified end to end against the reproduction in the ticket, on a non-git workspace with a PEM key and a Slack webhook URL:

invocation result
--changed-files auto fails with the new message, exit 1
--changed-files auto --scan-all logs the fail-open warning, widens to the workspace
INPUT_SCAN_ALL=true ... --no-scan-all fails closed, exit 1
INPUT_SCAN_ALL=true ... (no flag) environment value wins, widens

The widened runs stop at TruffleHog's missing-binary error on this machine, which is the documented fail-closed behavior from 3.2.0 rather than a regression; the scope resolution itself is what these exercise.

scripts/check_release_docs.py --check passes.


Fixes CE-455


Note

Low Risk
Small CLI/config parity change with explicit precedence rules and tests; no change to scan logic when scope resolves successfully.

Overview
Adds --scan-all and --no-scan-all so the CLI matches the existing scan_all action input, INPUT_SCAN_ALL, and JSON/dashboard settings. When --changed-files cannot be resolved, operators can opt into a full-workspace fallback from the command line instead of only via non-CLI config.

The flags use BooleanOptionalAction with default None: omitting both leaves env/JSON/dashboard values alone; --no-scan-all forces fail-closed for one run even when INPUT_SCAN_ALL is set. The unresolvable-scope SystemExit message now lists every way to enable the fallback (CLI, action input, env, config).

Docs (CHANGELOG, parameters.md, github-action.md) and TestScanAllCliFlag cover parsing, precedence, fallback behavior, and the updated error text.

Reviewed by Cursor Bugbot for commit ad685cc. Configure here.

lelia and others added 2 commits September 11, 2026 15:32
`scan_all` is the documented escape hatch when a `changed_files` scope
cannot be resolved, but it was reachable only from the GitHub Action
input, `INPUT_SCAN_ALL`, a `--config` JSON key or dashboard config. The
failure message told operators to "set scan_all" without saying how, and
on the CLI there was no way to follow that instruction at all — every
neighbouring scope setting (`--changed-files`, `--scan-files`,
`--workspace`) already had a flag.

Add the paired `--scan-all` / `--no-scan-all` form rather than a plain
`store_true`: the setting defaults to false but can already be on from
the environment, a config file or the dashboard, and a `store_true` flag
could never turn that back off. Absent, the flag parses to `None`, so it
never overwrites one of those sources with an implicit false.

The unresolvable-scope error now names the concrete remediation for each
interface instead of just the config key.

Refs CE-455

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Rewrite the new comments to state present-tense invariants rather than
the shape of the change: the declaration-site comment keeps only the
rationale for the paired flag form, the application site keeps only what
`None` must not do, and the test class docstring describes the constraint
the flag satisfies instead of what was missing before it.

Also use the repo's dominant American spelling in the --help string and
the docs that quote it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@lelia
lelia requested a review from a team as a code owner September 15, 2026 17:24
@lelia

lelia commented Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit ad685cc. Configure here.

@lelia lelia changed the title feat(config): add --scan-all and --no-scan-all CLI flags feat(config): add --scan-all and --no-scan-all CLI flags Sep 15, 2026
@lelia lelia mentioned this pull request Sep 15, 2026
7 tasks
#114 landed on main while this branch was open. Both sides added entries
under CHANGELOG [Unreleased] and nothing else overlapped, so the two
sections are kept side by side in Keep a Changelog order: Added and
Changed from this branch, Fixed from #114.
@lelia
lelia merged commit df8dfb5 into main Sep 15, 2026
22 checks passed
lelia added a commit that referenced this pull request Sep 15, 2026
Release prep for 3.3.0, bundling #114 and #115. #115 adds the
`--scan-all` / `--no-scan-all` CLI flags, so this is a minor bump
rather than a patch.

Bumps pyproject.toml, socket_basics/version.py, socket_basics/__init__.py,
action.yml and uv.lock to 3.3.0, synchronizes 83 current-release references
across README.md and docs/**, and stamps [Unreleased] as [3.3.0] - 2026-09-15.

Also pins the Socket Python CLI to 2.9.0 in Dockerfile.heavy and
app_tests/Dockerfile, ahead of that release publishing to PyPI.
lelia added a commit that referenced this pull request Sep 15, 2026
Release prep for 3.3.0, bundling #114 and #115. #115 adds the
`--scan-all` / `--no-scan-all` CLI flags, so this is a minor bump
rather than a patch.

Bumps pyproject.toml, socket_basics/version.py, socket_basics/__init__.py,
action.yml and uv.lock to 3.3.0, synchronizes 83 current-release references
across README.md and docs/**, and stamps [Unreleased] as [3.3.0] - 2026-09-15.

Also pins the Socket Python CLI to 2.9.0 in Dockerfile.heavy and
app_tests/Dockerfile, ahead of that release publishing to PyPI.
@lelia lelia mentioned this pull request Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants