Show HN: Socket web extension – free NPM supply chain protection Hey HN, I'm Arjun, an 18-year-old intern at Socket. I've been working on a project that I'm really excited to share with you all - a browser extension that makes it easier to check the security of NPM packages before you use them. You can try the extension on any Chromium-based browser or on Firefox. Chrome extension: https://ift.tt/gIcd5H4... Firefox add-on: https://ift.tt/VmSJiMX... Socket scans NPM packages for malware, vulnerabilities, code smell, and unwanted behavior using AI and some very powerful in-house static analysis we've been perfecting over the last 2 years. As the primary developer of Parcel.js' web extension transformer ( https://ift.tt/wdaXChA ), I thought it would be cool to use my own work on Parcel to create a useful extension during my internship at Socket. The extension displays scores alongside each package indicating quality, security, maintenance, and other useful metrics. It also tells you if a package accesses the network when it shouldn't need to, or if it runs malware in an install script. You can learn more about its features in my blog post: https://ift.tt/lb4vX3k Feel free to ask any questions you have about Socket, the extension or even my work on Parcel. Excited to hear your feedback! - Arjun https://ift.tt/kjoL9hl August 1, 2023 at 04:23AM
Show HN: Socket web extension – free NPM supply chain protection https://ift.tt/fxHpKDU
Related Articles
Show HN: Poser (Posix SERvices C framework) https://ift.tt/92jrObfShow HN: Poser (Posix SERvices C framework) https://ift.tt/XUsoPKf Jun… Read More
Show HN: FigMaps, a visual sitemap builder to plan websites and gather content https://ift.tt/oXUR78uShow HN: FigMaps, a visual sitemap builder to plan websites and gather… Read More
Show HN: Imuengine.io (NYC S23): Easily Process IMU Data in the Cloud https://ift.tt/TfZ4XUlShow HN: Imuengine.io (NYC S23): Easily Process IMU Data in the Cloud … Read More
Show HN: Roboduck, a GPT-powered Python debugger https://ift.tt/jLNn5aUShow HN: Roboduck, a GPT-powered Python debugger I made a python libra… Read More
Show HN: WebAssembly port of Neverball, a 3D rolling ball game https://ift.tt/THR7lzdShow HN: WebAssembly port of Neverball, a 3D rolling ball game Neverba… Read More
Show HN: Athena, a research paper recommender for overwhelmed AI researchers https://ift.tt/fw4RzxYShow HN: Athena, a research paper recommender for overwhelmed AI resea… Read More
Show HN: Autodistill – Use big slow foundation models to train small fast models https://ift.tt/wkx4nPhShow HN: Autodistill – Use big slow foundation models to train small f… Read More
Show HN: FemtoGPT – Pure Rust implementation of a GPT language model https://ift.tt/IwhjZqpShow HN: FemtoGPT – Pure Rust implementation of a GPT language model h… Read More
0 Comments: