{"categories":[{"label":"Quality Assurance","url":"https://skillfed.io/packages/category/software-development-quality-assurance/3"}],"enrichment":{"capability":"Socket Security CLI scans Python projects for supply-chain security risks, generates SARIF reports, and integrates with CI/CD pipelines to enforce security policies.","skillfed_tags":["supply-chain-security","ci-cd-integration","sarif-export"],"use_cases":["Gate pull requests in CI/CD by scanning diffs against a baseline commit and blocking merges if new security issues are found.","Generate SARIF reports for GitHub Advanced Security, GitLab Dependency Scanning, or other security dashboards.","Export legal/compliance artifacts (SBOM, license inventory) in standard or FOSSA-compatible formats for audit trails.","Analyze reachability of vulnerabilities to prioritize fixes based on whether issues are actually used in your code.","Enforce supply-chain security policies across teams by running scans on every commit to the default branch."],"what_it_does":"Socket Security CLI is a command-line tool that scans Python projects for supply-chain security issues\u2014vulnerabilities, policy violations, and license risks\u2014and reports results in multiple formats. It integrates directly into CI/CD pipelines to gate deployments based on security findings, with support for diff-based PR scanning, full-scope analysis, and reachability-aware filtering to reduce noise.\n\nThe tool connects to Socket's backend service via API token and can export findings as SARIF (for GitHub, GitLab, and other platforms), JSON reports, SBOMs, and legal/compliance artifacts. It supports both simple policy enforcement (exit on blocking issues) and detailed investigation workflows (full-scope SARIF with instance-level detail). Configuration is flexible\u2014via CLI flags, environment variables, or TOML/JSON config files\u2014and includes presets for common scenarios like legal compliance and FOSSA compatibility.","worth_installing":"Yes, if you need supply-chain security scanning in CI/CD. The tool is actively maintained, has low install friction, and integrates well with common platforms (GitHub, GitLab, Buildkite, Bitbucket). Requires Python 3.11+ and a Socket Security API token. No known vulnerabilities. MIT license is permissive. Start with a basic policy scan or SARIF export to evaluate fit."},"id":"socketsecurity","links":{"html":"https://skillfed.io/packages/socketsecurity","md":"https://skillfed.io/packages/socketsecurity.md","pypi":"https://pypi.org/project/socketsecurity/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-12","license_spdx":null,"license_treatment":"permissive","name":"socketsecurity","python_support":"supports_current","summary":"Socket Security CLI for CI/CD"},"popularity":{"monthly_downloads":220640,"position":9295,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"2.6.4"}
