
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@otakit/cli
Advanced tools
Upload and release CLI for OtaKit.
capacitor.config.*The normal hosted flow is dashboard-first. Create the app in the dashboard,
paste its appId into plugins.OtaKit.appId, then ship:
otakit login
npm run build
otakit upload --release
If you want to create the app from the CLI instead:
otakit register --slug com.example.app
There is no otakit init.
The CLI reads these files when present:
capacitor.config.tscapacitor.config.jscapacitor.config.mjscapacitor.config.cjscapacitor.config.jsonImportant values:
webDir: "out",
plugins: {
OtaKit: {
appId: "app_xxxxxxxx",
// Optional:
// channel: "staging",
// serverUrl: "https://your-server.com/api/v1"
}
}
Resolution order:
capacitor.config.*Main rules:
appId: --app-id -> OTAKIT_APP_ID -> plugins.OtaKit.appIdserverUrl: --server -> OTAKIT_SERVER_URL -> plugins.OtaKit.serverUrl -> https://otakit.app/api/v1outputDir: upload path arg -> OTAKIT_BUILD_DIR / OTAKIT_OUTPUT_DIR -> webDir--release -> unnamed channel, --release <channel> -> named channelAuth precedence:
OTAKIT_TOKENOTAKIT_ACCESS_TOKENotakit loginOTAKIT_SECRET_KEYVersion precedence:
--versionOTAKIT_VERSION<base>+otk.<commit>.<run>otakit upload
upload onlyotakit upload --release
upload and release to the unnamed channelotakit upload --release staging
upload and release to a named channelotakit release <bundleId> --channel staging
promote an existing bundle laterReleases are append-only. The newest release for (appId, channel) is what
devices see on manifest checks.
otakit loginotakit logoutotakit whoamiotakit register --slug <slug>otakit upload [path] [--release [channel]]otakit release [bundleId] [--channel <channel>]otakit releases [--channel <channel> | --base]otakit listotakit delete <bundleId> --forceotakit config validateotakit config resolve --jsonotakit generate-signing-keyexport OTAKIT_SECRET_KEY=otakit_sk_...
export OTAKIT_APP_ID=app_xxxxxxxx
export OTAKIT_BUILD_DIR=out
otakit upload --release
Set OTAKIT_SERVER_URL only for custom or self-hosted servers.
index.htmlbundles/initiatebundles/finalizereleasesThe CLI does not own app creation or channel strategy. It packages the build, uploads it, and optionally promotes it.
pnpm --filter @otakit/cli build
pnpm --filter @otakit/cli typecheck
pnpm --filter @otakit/cli dev
FAQs
CLI for uploading and releasing OtaKit OTA bundles
The npm package @otakit/cli receives a total of 2,234 weekly downloads. As such, @otakit/cli popularity was classified as popular.
We found that @otakit/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.