Security News
Opengrep Emerges as Open Source Alternative Amid Semgrep Licensing Controversy
Opengrep forks Semgrep to preserve open source SAST in response to controversial licensing changes.
Security News
Product
Sarah Gooding
March 12, 2024
Socket is built by a team of prolific open source maintainers whose software is downloaded over 1 billion times per month. We recognize that a thriving open source ecosystem is critical to technological advancement and securing this code is part of our mission.
Our team is intimately familiar with the dedication and effort required to contribute to projects that form the backbone of our digital world. We are keenly aware of the often unrecognized and unseen labor that open source teams invest in their projects—efforts that fuel the apps and critical infrastructure vital to modern life.
We want to give something back to honor these contributions to our industry. Socket is now offering a free upgrade to our Team plan for open source projects. This plan includes everything in the free plan with additional features like blocking rules for blocking the introduction of risky dependencies, organization-wide dependency search (query for any dependency across your organizations), Slack alerts, and dedicated support.
Socket protects open source code for some of the best engineering teams in the world, including Vercel, Storybook, Ant Design, Cal.com, Brave, Metamask, i18next, freeCodeCamp, and many other organizations. It goes beyond simple CVE scanning tools to block zero-day supply chain attacks and analyze dependencies for risky or malicious behavior, like typosquatting, malware, install scripts, network access, protestware, and more.
Our package dependency scores also help developers quickly evaluate the security and health of any open source package. Widely used open source projects are prime targets for bad actors looking to land a successful supply chain attack. Socket was created to prevent these malicious dependencies and updates from landing in your projects.
This program is open to any public open source project that is offered under a valid Open Source license. The process for upgrading your account is simple. Sign up for Socket for free, and then send an email to support@socket.dev with your GitHub organization name. We will upgrade your organization to the Team plan and you can begin enjoying the additional benefits right away.
Subscribe to our newsletter
Get notified when we publish new security blog posts!
Try it now
Security News
Opengrep forks Semgrep to preserve open source SAST in response to controversial licensing changes.
Security News
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
Security News
cURL and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are calling for more accurate, context-aware approaches.