security / Supply Chain
Socket.dev
4.6(87 reviews)
Overview
Supply chain security platform that detects malicious and risky open-source packages before they enter your codebase. Unlike traditional SCA tools that only check for known CVEs, Socket uses deep package inspection to analyze actual package behavior — network access, filesystem operations, shell execution, and install scripts — flagging packages that act suspiciously even without a published CVE.
Key Features
- Deep package inspection
- Behavioral analysis (network, fs, shell)
- Malicious package detection
- Typosquatting detection
- Dependency diff on PRs
- Install script analysis