Security News
The Risks of Misguided Research in Supply Chain Security
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Product
Sarah Gooding
July 25, 2024
We’ve got some exciting news to share – we’ve just launched our brand-new Product Changelog! While we don't always publish a full blog post for every update, we know it's important to keep you informed about improvements impacting your security experience.
The Socket Changelog is a new resource for tracking all the latest changes, improvements, and fixes to our product. Whether it's a new feature, a performance enhancement, or a bug fix, you’ll find it documented here. Our goal is to keep you informed about all the incremental changes that help make Socket more powerful and user-friendly.
This dedicated page ensures that even the smaller updates, which may not warrant a full blog post, are still communicated to you. This way, you’re always in the loop and can take full advantage of everything that’s new.
We invite you to visit our Changelog regularly to stay updated on the latest developments. Your continued support and feedback are invaluable as we keep working to make Socket the better every day. Thank you for being a part of the Socket community!
Subscribe to our newsletter
Get notified when we publish new security blog posts!
Try it now
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.