Socket

Supply chain security that blocks malicious dependencies at install time

About Socket

Socket statically analyzes open-source packages for malicious behavior such as suspicious install scripts, network calls, and exfiltration patterns. It blocks risky dependencies in pull requests and surfaces 70+ supply chain risk types beyond known CVEs. The platform integrates with GitHub and uses LLMs from Anthropic and OpenAI to summarize package risk.