
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@sentry/server-runtime-injection
Advanced tools
Runtime diagnostics-channel injection hooks for the Sentry JavaScript SDKs. Must be kept external (not bundled) when bundling a server.
Runtime instrumentation for Sentry’s JavaScript server SDKs.
[!NOTE] This package is an internal library published for use by Sentry-owned JavaScript SDK packages. It is not part of the public API contract and may change in any release. Do not rely on SemVer compatibility if you depend on it directly.
Important: this package must be kept external (not bundled) when bundling a server. Its runtime hook loads a transformer that self-references its own on-disk
node_moduleslocation; bundling it strips the transformer and breaks that self-reference. When you bundle your server, either keep@sentry/server-runtime-injectionexternal, or rely on the build-time instrumentation from the Sentry bundler plugins instead.
FAQs
Runtime diagnostics-channel injection hooks for the Sentry JavaScript SDKs. Must be kept external (not bundled) when bundling a server.
The npm package @sentry/server-runtime-injection receives a total of 1,580,395 weekly downloads. As such, @sentry/server-runtime-injection popularity was classified as popular.
We found that @sentry/server-runtime-injection demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.