diff --git a/src/commands/fix/cmd-fix.e2e.test.mts b/src/commands/fix/cmd-fix.e2e.test.mts index ac4b7f5a8..d0acab8b6 100644 --- a/src/commands/fix/cmd-fix.e2e.test.mts +++ b/src/commands/fix/cmd-fix.e2e.test.mts @@ -27,6 +27,12 @@ function getTestEnv(apiToken: string): Record { http_proxy: undefined, https_proxy: undefined, SOCKET_CLI_API_PROXY: undefined, + // A firewall proxy (e.g. sfw in CI) also points these at its own CA, which + // then becomes the only trusted root for direct connections. + GIT_SSL_CAINFO: undefined, + PIP_CERT: undefined, + SSL_CERT_DIR: undefined, + SSL_CERT_FILE: undefined, } } diff --git a/src/commands/scan/cmd-scan-reach.e2e.test.mts b/src/commands/scan/cmd-scan-reach.e2e.test.mts index 3ca0ced0a..d5787dac9 100644 --- a/src/commands/scan/cmd-scan-reach.e2e.test.mts +++ b/src/commands/scan/cmd-scan-reach.e2e.test.mts @@ -90,6 +90,12 @@ function getTestEnv(apiToken: string): Record { http_proxy: undefined, https_proxy: undefined, SOCKET_CLI_API_PROXY: undefined, + // A firewall proxy (e.g. sfw in CI) also points these at its own CA, which + // then becomes the only trusted root for direct connections. + GIT_SSL_CAINFO: undefined, + PIP_CERT: undefined, + SSL_CERT_DIR: undefined, + SSL_CERT_FILE: undefined, } } @@ -980,11 +986,6 @@ describe('socket scan reach (E2E tests)', async () => { // Coana v15 halts on by default. The test asserts on the ecosystem // filter, not source-file presence. '--reach-continue-on-no-source-files', - // The CI runner's network firewall blocks pypi.org, so the pypi - // pre-install step fails. Coana v15 halts on install errors by - // default; this test asserts on ecosystem-filter discovery, not - // successful installation. - '--reach-continue-on-install-errors', ], 'should only analyze pypi ecosystem when --reach-ecosystems pypi is specified', async cmd => {