fix(firewall): pin sfw v1.15.4 - #25
Merged
Merged
Conversation
sfw v1.15.4 restores the "not found in PATH" verdict for a command PowerShell genuinely cannot resolve on Windows (SocketDev/firewall#210); v1.15.3 reported that case as a resolver error. The action installs only the version its checksum table covers, so the fix is not installable through it until this bump. Recompute all twelve checksums from the published v1.15.4 assets and rebuild dist/. Also move findCachedFirewall above firewallDownloadUrls. #18 and #24 each passed lint on their own, but merging both left the export out of the alphabetical order the sort-source-methods rule wants, which fails lint on main and blocks any commit touching this file.
Julian Gruber (juliangruber)
marked this pull request as ready for review
October 1, 2026 12:08
Member
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pins the action to sfw v1.15.4 and recomputes all twelve checksums from the published assets.
v1.15.4 restores the "not found in PATH" verdict for a command PowerShell genuinely cannot resolve on Windows (SocketDev/firewall#210). v1.15.3 reported that case as a resolver error.
Checksums were computed locally from the downloaded release assets (
shasum -a 256); sizes match the release listing.Also moves
findCachedFirewallabovefirewallDownloadUrls: #18 and #24 each passed lint alone, but merged together they left the export out of the ordersort-source-methodswants, so lint fails onmainand the pre-commit hook blocks any commit touching this file.🤖 Generated with Claude Code
Note
Low Risk
Routine pinned-binary bump and checksum refresh with no download or validation logic changes; wrong hashes would fail at install time rather than silently running bad binaries.
Overview
Bumps the default Socket Firewall install from v1.15.3 to v1.15.4 by updating
FIREWALL_VERSIONand all twelve pinned SHA256 entries (enterprise and free, every supportedplatform-arch) insrc/tools/firewall.js, with the same constants reflected indist/main.js.v1.15.4 is the release that restores the correct “not found in PATH” verdict on Windows when PowerShell cannot resolve a command (instead of reporting a resolver error as in v1.15.3).
firewallDownloadUrlsis moved to sit afterfindCachedFirewallso export order matchessort-source-methodslint after prior merges; behavior of URL construction is unchanged.Reviewed by Cursor Bugbot for commit 5ab1c4d. Configure here.