
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@tdk-landscape/tdk-import
Advanced tools
Scan a repo and import its Procfile, Compose, Dockerfile and package.json services into TDK service.json files.
Scan a repo and import the services it describes into TDK as bring-your-own service.json files. Part of tdk-landscape/tdk-cli-core#511; the Procfile detector is tdk-landscape/tdk-cli-core#520.
npx -y @tdk-landscape/tdk-import@0.1.1 . --dry-run # plan only
npx -y @tdk-landscape/tdk-import@0.1.1 . --yes # write services/<stack>/<name>/service.json
Version 0.1.1 includes the unsupported-infrastructure refusal and Procfile skip safeguards from tdk-import#9. Use the pinned version above; 0.1.0 does not provide those guarantees.
The animation shows a three-line Procfile (web, worker, release) imported, then run through tdk project --yes, tdk config regenerate and tdk up. Every file listed was produced in a real run, including the .autogenerated folders that tdk up writes.
It reads Procfile, docker-compose*.yml, Dockerfile and package.json, merges what several files say about one service, lists conflicts instead of guessing, and never overwrites a service.json without --force. See docs/import.md for what maps, what is skipped, and how to add a detector, and openspec/changes/import-repo/ for the spec.
Use TDK CLI core 1.3.104 or later to start imported services. Version 1.3.104 is the first release with buildContext (tdk-cli-core#525, release 1.3.104). Upgrade TDK before running tdk up on imported services. If core 1.3.104 is not available in your environment, import cannot be started yet; do not run tdk up against an older core. The importer does not check the installed TDK version.
Commands beginning with node, npm, pnpm, yarn, or bun can be scaffolded. Other commands, including Python, Ruby, Gunicorn, and Poetry, are skipped unless a matching Dockerfile or image is present. A mixed Procfile imports the supported processes and reports the skipped ones; if every valid process is skipped, the command exits 2. Add a Dockerfile or image for a skipped process.
Status: checked through a real tdk up: an imported Compose + Dockerfile service and a Procfile (node) service both build, start and answer HTTP on $PORT.
Publishing: run the "Publish tdk-import" workflow in tdk-landscape/tdk-cli-core (manual, with a tag of this repo; dry_run is on by default). It uses that repo's NPM_TOKEN, which is not set here.
bun install && bun run build && bun run test
FAQs
Scan a repo and import its Procfile, Compose, Dockerfile and package.json services into TDK service.json files.
We found that @tdk-landscape/tdk-import demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.