5,756 open-source and SaaS tools, with GitHub stats refreshed every day.

Socket

SaaS

Supply chain security tool that flags risky or malicious open source packages before they are installed in a project.

socket.dev
Socket homepage screenshot

About Socket

Socket is a commercial supply chain security product for software teams that rely on open source packages. Its aim is to detect risky or malicious dependencies before they get installed, rather than only reporting known vulnerabilities after the fact. It is relevant to developers and security teams who manage large dependency trees.

The vendor site could not be read when this entry was prepared, so only the high-level scope is described here. Socket is delivered as a hosted service and is proprietary; teams should consult the vendor for supported ecosystems, integration options and pricing.

Key features

  • Detects risky open source packages
  • Checks dependencies before installation
  • Focus on software supply chain attacks
  • Hosted service for development teams

Good fit for

  • →Vetting new dependencies before adding them
Tags
security
supply-chain
dependencies
open-source
appsec
devsecops

Open-source alternatives to Socket

See all

SaaS alternatives to Socket

See all