
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@earendil-works/pi-codemode
Advanced tools
Placeholder to register the package name. Real releases are published from https://github.com/earendil-works/pi.
Placeholder release that registers the package name. Real releases are published from https://github.com/earendil-works/pi.
FAQs
Sandboxed JavaScript execution where the only capability is calling injected tools
The npm package @earendil-works/pi-codemode receives a total of 1,266,456 weekly downloads. As such, @earendil-works/pi-codemode popularity was classified as popular.
We found that @earendil-works/pi-codemode demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.