
Product
Introducing Webhook Events for Pull Request Scans
Add real-time Socket webhook events to your workflows to automatically receive pull request scan results and security alerts in real time.
[!WARNING] This was mostly made to suit my needs, some things may or may not work for you and I do not spend a lot of time maintaining it, use at your own risk.
A vanity URL service for Go packages (modules, projects and executables)
You can install Vanity with Go:
go install go.trulyao.dev/vanity@latest
Run the following command to create a config file:
vanity --init
Optionally, you can use --config=[path] flag to customize your config file location and name. You can now run Vanity by using the following command:
vanity --config=path/to/config.json
Docker is the recommended way to use Vanity but I haven't taken time to setup the workflow yet (there aren't even versions yet at this point) but you can use the unofficially supported image or build from source.
docker pull trulyao/vanity:latest
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Add real-time Socket webhook events to your workflows to automatically receive pull request scan results and security alerts in real time.

Research
The Socket Threat Research Team uncovered malicious NuGet packages typosquatting the popular Nethereum project to steal wallet keys.

Product
A single platform for static analysis, secrets detection, container scanning, and CVE checks—built on trusted open source tools, ready to run out of the box.