Socket

フィード

記事のアイキャッチ画像
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages
Socket
Miasma Mini Shai-Hulud hits @immobiliarelabs Backstage plugins, targeting GitLab and LDAP auth packages on npm.
2日前
記事のアイキャッチ画像
Rolldown Pulls Rust React Compiler Integration After Binary Size Increase
Socket
Rolldown paused Rust React Compiler integration after a 5MB binary size increase raised concerns about shipping React-specific code to all Vite users.
2日前
記事のアイキャッチ画像
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem
Socket
Mini Shai-Hulud expands into the Go ecosystem after hitting LeoPlatform npm packages and targeting GitHub Actions workflows.
3日前
記事のアイキャッチ画像
Frontier AI Is Now Critical Infrastructure
Socket
The Fable shutdown shows how quickly model access can become a business continuity risk for AI-dependent engineering teams.
4日前
記事のアイキャッチ画像
The Code You Didn't Write Is Still Yours to Defend
Socket
AI agents are pulling packages into environments no scanner is watching, creating exposure before security teams can see it.
5日前
記事のアイキャッチ画像
GitHub Actions Checkout Now Blocks Risky pull_request_target Checkouts
Socket
GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks.
8日前
記事のアイキャッチ画像
Introducing Repository Access Permissions and Custom Roles
Socket
Socket now supports Custom Roles and Repository Access Permissions so organizations can control who can access specific repositories and actions.
9日前
記事のアイキャッチ画像
Socket MCP Adds Org Alerts, Threat Feed Review, and Package Inspection
Socket
Socket MCP now lets AI assistants review org alerts, investigate threats using the Socket threat feed, and inspect package files in addition to dependency scoring.
10日前
記事のアイキャッチ画像
Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions
Socket
Socket Firewall blocks malicious VS Code and Open VSX extensions before install, protecting developers from compromised editor marketplaces.
11日前
記事のアイキャッチ画像
140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack
Socket
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infostealer during installation.
11日前