New:Socket for Asana Is Now Available.Learn more
Get Started

Slack integration

Socket for Slack

Send Socket's supply chain alerts straight to the channels your team already watches. This page covers installing the app, choosing what it posts, and exactly how it behaves once it is running.

Go to your dashboardCreate a free account

What the Slack app does

Once connected, Socket posts to Slack as things happen.

Supply chain alerts delivered to the channels your team already watches.

Route different alerts to different channels, so each team only hears what concerns it.

Connect more than one Slack workspace to a single Socket organization.

Where the install button lives

Socket for Slack is installed from your organization's settings rather than from this page, so the install button sits behind a login. The instructions below cover how to reach it, including what to do if you do not have an account yet.

Before you begin

Five things to check before you start.

A Socket account and an organization to install into. Create a free account

A plan that includes chat integrations — Team, Business, or Enterprise. Slack is not part of the Free plan. Compare plans

A role that can change integration settings, such as organization owner or admin.

Permission to install apps in your Slack workspace. Some workspaces require an admin to approve new apps, so you may need to send a request.

Socket for Slack is rolling out to organizations gradually, so the Slack section may not be in your settings yet. If it is missing, reach out and we will turn it on for your organization.

Install the Socket app in Slack

Six steps, from a signed-out browser to a connected workspace.

1

Sign in to Socket

Sign in at socket.dev. If you do not have an account yet, create one first — signing up is free and takes a minute.

2

Choose your organization

Use the organization switcher at the top of the dashboard sidebar to select the organization that should receive Slack alerts.

3

Open Settings, then Slack

Select Settings in the sidebar, then pick Slack from the Integrations group. You can also go straight there at socket.dev/dashboard/org/YOUR-ORG/settings/integrations/slack, replacing YOUR-ORG with your organization's slug.

4

Select Connect Slack

In the Slack Installations section, select Connect Slack. Workspaces you have already connected are listed here instead.

5

Approve the app in Slack

Slack opens its own authorization screen. Pick the workspace you want Socket added to, review the permissions it asks for, and select Allow.

6

Land back in Socket

Slack sends you back to Socket and the workspace shows up under Slack Installations. If you began the install without picking an organization, Socket asks which one to link the workspace to.

Configure what Socket sends

Connecting the workspace gives Socket permission to post. Subscriptions decide what gets posted and where.

1

Open your notification settings

Go to Settings, then Notifications under the Integrations group.

2

Add your workspace as a channel

Select Create Channel, choose Slack as the type, pick the workspace you connected, and create it. Socket syncs that workspace's channels so you can choose between them in a moment.

3

Create a subscription

In the Subscriptions section, select Create Subscription and pick the event you want to hear about. A subscription is what actually turns messages on — until you create one, Socket posts nothing.

4

Filter what qualifies

Narrow the subscription down by category, severity, priority or repository, so a channel only gets what its team cares about. Leave the filter empty to receive every matching event.

5

Pick the destination channels

Choose the Slack channels that should receive this subscription, then select Create. Socket can post to public channels without being invited; for a private channel, add the Socket app to that channel in Slack first.

What makes Socket post

Socket posts only when something you subscribed to happens. Until you create a subscription, the app stays silent.

A new security alert appears in your organization, such as a vulnerability, a malware finding, or a license problem in one of your dependencies.

An existing alert changes — for instance its severity or its status moves.

An alert is cleared, so your team knows when something has been resolved.

Socket detects a supply chain attack campaign that impacts one of your repositories. This event is available where it has been enabled for your organization.

Alerts arrive grouped rather than one at a time. Socket collects everything from roughly a twenty minute window and posts a single summary.

The separate Slack Webhook setting posts a pull request report when a scan finds new alerts on a PR. That path uses an incoming webhook URL you paste into Socket, not the Slack app described above.

Nothing else posts to Slack. Socket does not post on a schedule, and it never posts to a channel you have not chosen.

What the messages look like

Everything Socket posts is a notification you can read at a glance and follow into the dashboard.

An alert message names your organization and the alert, along with its type, severity and status, and links to that alert in your Socket dashboard.

A grouped message shows the total number of alerts, a breakdown by priority, how many repositories are affected, a list of alert titles, and a link to the dashboard.

An attack campaign message names the campaign, describes it, lists the impacted repositories, and links to the campaign details.

Messages are plain text with links. There are no buttons to press, and Socket never sends direct messages to individual people.

Does the Socket bot reply?

No. Socket for Slack only sends messages — it never reads or answers them.

There are no slash commands. Typing at the Socket bot does nothing.

Mentioning the Socket app in a channel does not trigger a reply.

Socket does not ask for permission to read your conversations and cannot see what your team writes.

The only workspace activity Socket listens for is housekeeping — a channel being created, renamed, archived or deleted, your workspace being renamed, and the app being uninstalled. Socket uses these to keep its channel list accurate, and none of them produce a message.

What Socket asks for

Slack shows you this list before you approve anything. Here is what each item is used for.

See the public channels in your workspace, so you can choose one from a list.

See private channels the Socket app has been added to.

Post alert messages to the channels you pick.

Post to a public channel without needing an invite to it first.

Read your workspace's name and ID, so you can tell connected workspaces apart.

Socket only posts messages. It never reads the contents of your conversations.

Removing the app

You can disconnect at any time.

In Slack, open your workspace settings, go to Manage apps, select Socket, and remove it. This revokes the permissions you granted.

In Socket, the Configure link next to a connected workspace opens that workspace's app management page in Slack.

Need a hand?

If the Slack section is missing from your settings, or the workspace does not appear after you approve the install, get in touch and we will take a look.