
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
Control panel for local development. The local fleet is the apps and sites you keep, plus the ports they listen on.
Control panel for local development.
One control panel for the repos you choose. See which ones have uncommitted work, unpushed commits, unpublished versions, or dependents pinned to an old release. Then act from the same board: commit, push, publish, bump versions, update dependents, and start or stop dev servers. Every write opens a plan first and waits for you to confirm.
The controls depend on where you open it:
http://127.0.0.1:4321, on the machine that runs localhelm serve: every read and every write./deck, from a phone or any other device on your LAN or Tailscale: read-only. One tile per running app that has a LocalSlip claim and listens beyond 127.0.0.1. Tap to open, long-press to copy the link. No commit, publish, start, or stop. Write requests from anywhere but loopback get a 403.Start and stop need LocalSlip. The Sites tab needs a FilePress site. Both are optional. LocalSlip is the slip. LocalHelm is the wheel.
pnpm add -g localhelm
# or from a checkout:
pnpm install && pnpm build
# From the folder that contains your repos:
localhelm serve
Open http://127.0.0.1:4321. Click Add projects, scan that folder (. is where you ran serve), tick the ones you keep, and confirm. Nothing auto-enrolls.
The same actions exist on the CLI if you want them. scan, status, and deps only read. Other commands print a plan; --apply writes. publish, push, ship, and global need named ids. Never --force.
localhelm scan .
localhelm enroll ./my-cli ./my-lib --apply
localhelm status
localhelm serve --free-port # stop the named pid on that port, then serve
Menu Main / Demo (or localhelm serve --demo) is a sandbox fleet (localhelm.fleet.demo.json). Add and remove stay off the main file. Clear demo wipes only that sandbox. Commit, publish, push, and Land stay off.
localhelm serve opens the dashboard on port 4321. A global install runs the packaged board (SSR deps are bundled; no app/ needed). A checkout still uses Vite. Serve from the same tree as localhelm.fleet.json (or a child) or the board stays empty. If that port is already taken, serve names the pid and stops. Re-run with --free-port to stop it and bind. Never --force. Writes stay on loopback.
Skip folders with .localhelmignore at the workspace, or ~/.localhelm/ignore.
Commit-message drafts send repository text to Ollama on 127.0.0.1:11434 by default. For a remote host, explicitly set LOCALHELM_OLLAMA_MACHINE or LOCALHELM_OLLAMA_URL; LOCALHELM_OLLAMA_MODEL selects the model. The CLI and commit dialog name the destination. Drafting never scans the LAN or selects a cached remote host. Use ollanet scan --lan separately if you want discovery, then select the host. When Ollama is unavailable, the editable fallback message remains.
Requires Node 22+. License Apache-2.0. Site: localhelm.dev.
FAQs
Control panel for local development. The local fleet is the apps and sites you keep, plus the ports they listen on.
The npm package localhelm receives a total of 466 weekly downloads. As such, localhelm popularity was classified as not popular.
We found that localhelm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.