
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
HEIDES installer. Downloads the prebuilt HEIDES binary for your platform and exposes the heides command. Deterministic code analysis harness for AI agents.
Installs the prebuilt HEIDES binary for your platform and exposes the heides command. HEIDES is a deterministic code analysis harness that gives AI agents senses, memory and judgment for code.
npm install -g heides
heides --help
On install, the matching binary is downloaded from GitHub Releases into the package bin/ folder. No Rust toolchain needed.
| OS | Arch | Asset |
|---|---|---|
| Linux (glibc) | x64 | heides-x86_64-unknown-linux-gnu |
| macOS | arm64 | heides-aarch64-apple-darwin |
| macOS | x64 | heides-x86_64-apple-darwin |
| Windows | x64 | heides-x86_64-pc-windows-msvc.exe |
Not listed, e.g. Linux arm64, Android, or musl/Alpine: the installer stops with a clear error. Install from source instead (cargo install heides) or pick a build from the releases page.
Same as the native binary:
heides scan .
heides check .
heides mcp # MCP server over stdio for agents
npm package version tracks the HEIDES release version. heides@0.13.1 installs HEIDES 0.13.1.
npm uninstall -g heides
MIT. See LICENSE. Binary builds follow the HEIDES repo license.
FAQs
HEIDES installer. Downloads the prebuilt HEIDES binary for your platform and exposes the heides command. Deterministic code analysis harness for AI agents.
The npm package heides receives a total of 1,960 weekly downloads. As such, heides popularity was classified as popular.
We found that heides demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.