CLI tool for Socket.dev security analysis of npm dependencies. Current stable version is 1.1.86, with a history of active releases (multiple releases in 2025). Provides commands for scanning, fixing CVEs, optimizing dependencies, and managing security patches. Key differentiators: wraps npm/npx for real-time security scanning, supports SBOM generation via cdxgen, offers automated CVE fixing and dependency optimization via @socketregistry overrides. ESM-only, requires Node.js >=18.20.8 and pnpm >=10.33.0.
npm install socketVerified import paths — ran on the pinned version, not inferred.
Demonstrates programmatic usage of socket CLI with environment variable configuration and dry-run mode.
Use import or dynamic import() instead of require().
Upgrade Node.js to >=18.20.8 or use an older version of socket CLI.
Use --dry-run to preview changes before actually running commands.
Check release notes for replacement tools or migration guides.
Update to socket@0.14.39 or later which replaces 'tiny-colors' with 'yoctocolors-cjs'.
Change to import('socket') or use dynamic import.Upgrade Node to >=18.20.8 or downgrade socket to v0.14.65.
No dependency data recorded yet.