
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@layers/cli
Advanced tools
npm install -g @layers/cli fetches the layers binary for your platform (macOS, Linux, and Windows, x64 and arm64) and verifies its SHA256 against the release's checksums.txt before installing it.
Run layers setup in a repo to bind it to the Layers MCP, or layers --help for everything else.
CI publishes this package. The npm-publish job in
.github/workflows/release-cli.yaml runs on a cli/v* tag and authenticates to
npm with OIDC through npm trusted publishing. There is no npm token.
One-time setup on npmjs.com, required once per package before the first CI publish:
@layers/cli package page and go to Settings.layers, the repository to layers,
the workflow filename to release-cli.yaml, and the environment to
npm-publish.Until npm holds that record, the publish step fails with E404 or E403.
FAQs
Layers CLI: connect a repo to the Layers Growth MCP from the terminal.
The npm package @layers/cli receives a total of 62 weekly downloads. As such, @layers/cli popularity was classified as not popular.
We found that @layers/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.