
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
previewdrop
Advanced tools
CLI for PreviewDrop — live preview environments for every branch. Any Dockerfile, any stack.
A live URL for every branch. Any app, any stack.
Command-line companion to previewdrop.dev — isolated preview environments for every branch you push. Point PreviewDrop at a Dockerfile (Django, Rails, Laravel, FastAPI, Next.js, Go, Rust — anything) and get a shareable HTTPS URL in under 60 seconds. Open a PR and the URL lands as a bot comment. Merge the PR and the preview cleans itself up.
This CLI lets you trigger deploys, watch builds, tail logs, and destroy previews straight from your terminal — or wire it into CI/CD.
# Global
npm install -g previewdrop
# Or run ad-hoc
npx previewdrop <command>
Requires Node.js 18+
You need a PreviewDrop account and at least one connected repo. Sign up free at previewdrop.dev and install the GitHub App — takes under a minute. Then:
# 1. Authenticate the CLI (opens your browser)
previewdrop login
# 2. Find your project ID
previewdrop list projects
# 3. Deploy any branch and wait for a live URL
previewdrop deploy <project-id> --branch feat/new-ui --wait
You'll see something like:
✓ Deployment started: a1b2c3d4-e5f6-7890-abcd-ef1234567890
Preview URL: https://prv-a8c2f9.previews.previewdrop.dev
⠼ Status: building…
✓ Deployment ready!
https://prv-a8c2f9.previews.previewdrop.dev
That URL is a full isolated environment. Share it with designers, PMs, QA, or clients — no VPN, no staging contention, no localhost tunneling.
login — authenticatepreviewdrop login [--key <api-key>] [--host <url>]
Opens your browser to generate an API key and stores it locally (under ~/.config/previewdrop). For CI, pass a token directly:
previewdrop login --key $PREVIEWDROP_API_KEY
list — discover projects and deploymentspreviewdrop list projects
previewdrop list deployments <project-id> [--limit <n>]
deploy — trigger a previewpreviewdrop deploy <project-id> [--branch <branch>] [--wait]
--branch — any branch name (defaults to the project's configured default branch)--wait — block until the deployment reaches a terminal state. Exits 0 on ready, 1 on failed/stopped/expired. Makes this safe to drop into CI.status — inspect a deploymentpreviewdrop status <deployment-id> [--watch]
Possible states: queued · building · deploying · ready · failed · stopped · expired.
--watch polls until a terminal state is reached, showing the live status inline.
logs — build + runtime logspreviewdrop logs <deployment-id> # build log (nixpacks / Dockerfile output)
previewdrop logs <deployment-id> --runtime # container stdout/stderr
previewdrop logs <deployment-id> --runtime --tail 500
Build logs include auto-detected diagnostics for common failures (missing env vars, lockfile conflicts, port binding issues, unsupported runtimes). Runtime logs are colour-coded by severity so errors jump off the page.
destroy — tear down a previewpreviewdrop destroy <deployment-id> [--yes]
Stops the container and marks the deployment as stopped. --yes skips the confirmation prompt for scripts.
The primary reason the CLI exists. Every preview gets a unique HTTPS URL, so your pipeline can post it to Slack, attach it to a GitHub PR comment, or feed it into Playwright / Cypress for end-to-end tests against a real environment.
name: Deploy preview
on: pull_request
jobs:
preview:
runs-on: ubuntu-latest
steps:
- uses: actions/setup-node@v4
with: { node-version: 20 }
- run: npm install -g previewdrop
- run: previewdrop login --key ${{ secrets.PREVIEWDROP_API_KEY }}
- name: Deploy branch
run: previewdrop deploy ${{ secrets.PROJECT_ID }} --branch ${{ github.head_ref }} --wait
PreviewDrop already posts a bot comment + commit status check when the GitHub App sees the PR — this Action is for cases where you need the URL inside another job (e.g. for E2E tests), or where you run CI on a different platform.
The CLI is a plain Node binary with a well-defined exit code, so it drops into any CI. Store PREVIEWDROP_API_KEY as a secret and run:
npm install -g previewdrop
previewdrop login --key "$PREVIEWDROP_API_KEY"
previewdrop deploy "$PROJECT_ID" --branch "$BRANCH_NAME" --wait
Exit 0 = ready · Exit 1 = failed/stopped/expired.
Anything PreviewDrop's build layer can auto-detect or containerise via a Dockerfile:
No YAML. No Kubernetes. No build-pipeline edits. No per-service resource tuning — one flat workspace price covers everything.
MIT — © 2026 Global Software Development SRL
FAQs
CLI for PreviewDrop — live preview environments for every branch. Any Dockerfile, any stack.
The npm package previewdrop receives a total of 25 weekly downloads. As such, previewdrop popularity was classified as not popular.
We found that previewdrop demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.