
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@tsrx/solid-runtime
Advanced tools
@tsrx/solid-runtimeSmall runtime helper package for Solid components compiled from TSRX.
Applications that compile .tsrx files can continue installing @tsrx/solid
alone with the default runtimeImports: 'compiler' mode.
When a compiler or build integration uses runtimeImports: 'direct', the package
that owns the source or generated modules must declare this runtime as a direct
production dependency:
pnpm add @tsrx/solid-runtime
The generated modules contain bare @tsrx/solid-runtime/* imports. A builder may
bundle those helpers or leave them external, but it does not provide this package;
the import must be resolvable during the build. Do not rely on dependency hoisting
or on @tsrx/solid installing the runtime transitively. Published component
libraries can keep the compiler and build integration in devDependencies while
declaring this package in dependencies.
Available subpath:
@tsrx/solid-runtime/refFAQs
Runtime helpers for TSRX Solid compiled output
The npm package @tsrx/solid-runtime receives a total of 1,203 weekly downloads. As such, @tsrx/solid-runtime popularity was classified as popular.
We found that @tsrx/solid-runtime demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.