No more refreshing dashboards. Socket now pushes every new, updated, or cleared alert straight into your workflow in real time.
Perfect way to wrap Launch Week: Ruby reachability, Certified Patches, Bun/vlt, OpenVSX… and now this ⚡️
No more refreshing dashboards. Socket now pushes every new, updated, or cleared alert straight into your workflow in real time.
Perfect way to wrap Launch Week: Ruby reachability, Certified Patches, Bun/vlt, OpenVSX… and now this ⚡️
VS Code extensions get full access to your code and creds, and attackers have already slipped malware into VS Code Marketplace and OpenVSX.
So Socket now scans OpenVSX extensions before they ever hit your machine. 🔍⚡️
VS Code extensions get full access to your code and creds, and attackers have already slipped malware into VS Code Marketplace and OpenVSX.
So Socket now scans OpenVSX extensions before they ever hit your machine. 🔍⚡️
You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
You no longer have to choose between innovation and security. Commit a bun.lock or vlt-lock.json and Socket gives you full supply chain protection.
cc: @campuscodi.risky.biz
Read the full analysis → socket.dev/blog/npm-mal...
cc: @campuscodi.risky.biz
(cont'd)
cc: @campuscodi.risky.biz
→ socket.dev/blog/malicio... #crypto
cc: @campuscodi.risky.biz
cc: @campuscodi.risky.biz
Read the full analysis → socket.dev/blog/9-malic... #dotnet
cc: @campuscodi.risky.biz
@sarahgooding.bsky.social @socket.dev
socket.dev/blog/the-cha...
#ECMAScript #JavaScript
@sarahgooding.bsky.social @socket.dev
socket.dev/blog/the-cha...
#ECMAScript #JavaScript
On the @changelog.com podcast, @feross.bsky.social shares practical steps every developer should take to reduce exposure to supply chain attacks on npm. →
socket.dev/blog/the-cha... #NodeJS #JavaScript
On the @changelog.com podcast, @feross.bsky.social shares practical steps every developer should take to reduce exposure to supply chain attacks on npm. →
socket.dev/blog/the-cha... #NodeJS #JavaScript
And it’s published via MIT with their chief security persons name on it.
And it’s published via MIT with their chief security persons name on it.
socket.dev/blog/securit...
h/t @doublepulsar.com
cc: @campuscodi.risky.biz
socket.dev/blog/securit...
h/t @doublepulsar.com
cc: @campuscodi.risky.biz
cc: @campuscodi.risky.biz
cc: @campuscodi.risky.biz
Read more: socket.dev/blog/malicio...
And we’re starting big: Today we're introducing malware scanning for the Hugging Face ecosystem! #HuggingFace
And we’re starting big: Today we're introducing malware scanning for the Hugging Face ecosystem! #HuggingFace
Beyond building new features, our recipients guide others, maintain essential systems, document the hard parts, and strengthen the community every step of the way. 💙
Read more about our honorees here: hubs.la/Q03NQvx10
Targets include Web3, cryptocurrency, and blockchain developers, as well as technical job seekers approached with recruiting lures, leading to multi-stage compromise and financial loss.
cc: @campuscodi.risky.biz
Full Report →
socket.dev/blog/north-k... #NodeJS
Targets include Web3, cryptocurrency, and blockchain developers, as well as technical job seekers approached with recruiting lures, leading to multi-stage compromise and financial loss.
cc: @campuscodi.risky.biz
An overview on the latest news from the Ruby gems packaging ecosystem with comments from @indirect.io and @duckinator.bsky.social:
socket.dev/blog/ruby-ce...
cc: @shortruby.com
An overview on the latest news from the Ruby gems packaging ecosystem with comments from @indirect.io and @duckinator.bsky.social:
cc: @campuscodi.risky.biz
Learn more → socket.dev/blog/google-...
cc: @campuscodi.risky.biz
@dale.link @socket.dev
socket.dev/blog/introdu...
#ECMAScript #JavaScript
@dale.link @socket.dev
socket.dev/blog/introdu...
#ECMAScript #JavaScript
If you haven't yet, you should install @socket.dev for your team!
We spoke with the team behind it. Read the full story on the Socket blog → socket.dev/blog/gem-coo... #RubyLang #Ruby #Rails
We spoke with the team behind it. Read the full story on the Socket blog → socket.dev/blog/gem-coo... #RubyLang #Ruby #Rails
@thisweekinrust.bsky.social @campuscodi.risky.biz
#rustlang
Starting today, that ends.
We’re releasing Socket Firewall — FREE, zero-config, CLI that blocks malware before it lands on your laptop or CI.
Just run:
npm i -g sfw
sfw npm install lodash
Works for: npm, yarn, pnpm, pip, uv, and cargo.
@thisweekinrust.bsky.social @campuscodi.risky.biz
#rustlang