Socket is free for open source maintainers. We're launching the Socket for Open Source program -- any open source maintainer can get a free Team plan to protect their project from supply chain attacks. Open source is critical infrastructure. Millions of companies depend on packages maintained by small teams and volunteers. These maintainers are high-value targets but rarely have access to enterprise security tooling. That's wrong. We want to fix it. What you get: ✅ Full dependency scanning across your project ✅ Real-time alerts for malicious packages in your dependency tree ✅ Check every PR to make sure no malicious dependencies are added -- including PRs from outside contributors If you maintain an open source project, send an email to support[at]socket[dot]dev and we'll get you set up!
Feross Aboukhadijeh I noticed you guys are hiring and was wondering if I might be considered. I would also be interested in using socket for some of my projects.
Nice! Perhaps I should set it up for https://sequins.dev. 🤔
Great move. Open source maintainers carry absurd amounts of risk for free, so putting real security tooling in their hands is genuinely valuable. Big respect for giving back to the OSS community 👏
this is awesome. a great contribution to the world, needed now more than ever
Nice, already using it for NodeSecure (PRs and recently sfw in CI). I just sent an email :)
Way to lead and support the industry!!! Love that you all are doing this and I hope others follow. Open source is the backbone of the technology industry and we need to support maintainers any way we can!
Amazing!
Thanks for this! sent an email
Does someone know how Socket differs from GitHub's dependabot?