
Security News
New Website “Is It Really FOSS?” Tracks Transparency in Open Source Distribution Models
A new site reviews software projects to reveal if they’re truly FOSS, making complex licensing and distribution models easy to understand.
Sarah Gooding
March 12, 2024
Socket is built by a team of prolific open source maintainers whose software is downloaded over 1 billion times per month. We recognize that a thriving open source ecosystem is critical to technological advancement and securing this code is part of our mission.
Our team is intimately familiar with the dedication and effort required to contribute to projects that form the backbone of our digital world. We are keenly aware of the often unrecognized and unseen labor that open source teams invest in their projects—efforts that fuel the apps and critical infrastructure vital to modern life.
We want to give something back to honor these contributions to our industry. Socket is now offering a free upgrade to our Team plan for open source projects. This plan includes everything in the free plan with additional features like blocking rules for blocking the introduction of risky dependencies, organization-wide dependency search (query for any dependency across your organizations), Slack alerts, and dedicated support.
Socket protects open source code for some of the best engineering teams in the world, including Vercel, Storybook, Ant Design, Cal.com, Brave, Metamask, i18next, freeCodeCamp, and many other organizations. It goes beyond simple CVE scanning tools to block zero-day supply chain attacks and analyze dependencies for risky or malicious behavior, like typosquatting, malware, install scripts, network access, protestware, and more.
Our package dependency scores also help developers quickly evaluate the security and health of any open source package. Widely used open source projects are prime targets for bad actors looking to land a successful supply chain attack. Socket was created to prevent these malicious dependencies and updates from landing in your projects.
This program is open to any public open source project that is offered under a valid Open Source license. The process for upgrading your account is simple. Sign up for Socket for free, and then send an email to support@socket.dev with your GitHub organization name. We will upgrade your organization to the Team plan and you can begin enjoying the additional benefits right away.
Subscribe to our newsletter
Get notified when we publish new security blog posts!
Try it now
Security News
A new site reviews software projects to reveal if they’re truly FOSS, making complex licensing and distribution models easy to understand.
Security News
Astral unveils pyx, a Python-native package registry in beta, designed to speed installs, enhance security, and integrate deeply with uv.
Security News
The Latio podcast explores how static and runtime reachability help teams prioritize exploitable vulnerabilities and streamline AppSec workflows.