$npx skillfedfor your agent

socketdev

Socket Security Python SDK

Worth itPyPI SecurityReleased Aug 2026238.2K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — socketdev-3.5.0-py3-none-any.whl
v3.5.0 · released 2026-08-06 · Python >=3.9 · 2 runtime deps: requests, typing-extensions

Yes. The SDK is actively maintained, has no known vulnerabilities, installs with minimal friction, and is licensed permissively under MIT. Install it if you need programmatic access to Socket.dev's package security API from Python; skip it if you only need one-off lookups via the web UI.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a valid Socket.dev API token; unauthenticated calls will fail.
  • Low friction: pure Python wheel with only two runtime dependencies (requests and typing-extensions).
  • Active maintenance with a release 8 days ago; repo shows recent commits and is not archived.

License · maintenance · safety

permissive license (permissive) — MIT License permits free use, modification, and distribution with minimal restrictions—suitable for commercial and open-source projects alike.

last release 2026-08-06 (8 days) · last repo commit 2026-08-11 · 13 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 238,203 downloads/mo, #8,944 on PyPI

Verify before relying

pip install socketdev

from socketdev import socketdev
socket = socketdev(token="YOUR_API_KEY")
result = socket.purl.post("true", [{"purl": "pkg:pypi/requests"}])
  • Whether the SDK supports all current Socket.dev API endpoints or only a subset of v0.
  • Rate limiting behavior and retry logic when making API calls.
  • Whether SSL verification can be disabled safely in production contexts beyond testing.
Same gist for agents: .md · .json

What it is and what it does

The Socket.dev Python SDK is a lightweight wrapper around the Socket.dev REST API that lets you query package metadata, security scores, and license information directly from Python. It handles authentication, request formatting, and response parsing so you don't have to build HTTP calls manually. The SDK supports querying packages by PURL (Package URL), running full scans on manifest files, and exporting SBOMs in multiple formats (CycloneDX, SPDX, OpenVEX).

You initialize it with an API token and optional timeout, then call methods like `purl.post()` to look up package details, `fullscans.post()` to analyze a set of manifest files, or `export.cdx_bom()` to convert scan results into standard SBOM formats. It depends only on requests for HTTP calls and typing-extensions for type hints, making it straightforward to integrate into existing Python projects.

Use it for

  • Query package metadata and security scores for dependencies in your codebase by PURL.
  • Automate full scans of manifest files (package.json, requirements.txt, etc.) as part of CI/CD pipelines.
  • Export SBOMs in CycloneDX or SPDX format for compliance and supply-chain visibility.
  • Retrieve vulnerability and license alerts for a set of components to inform security decisions.
  • Integrate Socket.dev security checks into custom tooling or dashboards.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

The SDK is actively maintained, has no known vulnerabilities, installs with minimal friction, and is licensed permissively under MIT. Install it if you need programmatic access to Socket.dev's package security API from Python; skip it if you only need one-off lookups via the web UI.

Install

socketdev on PyPI

Before you install

Low friction: pure Python wheel with only two runtime dependencies (requests and typing-extensions). Active maintenance with a release 8 days ago; repo shows recent commits and is not archived.

Requires a valid Socket.dev API token; unauthenticated calls will fail.

License in practice

MIT License permits free use, modification, and distribution with minimal restrictions—suitable for commercial and open-source projects alike.

Quickstart

pip install socketdev

from socketdev import socketdev
socket = socketdev(token="YOUR_API_KEY")
result = socket.purl.post("true", [{"purl": "pkg:pypi/requests"}])

Verify before relying

  • Whether the SDK supports all current Socket.dev API endpoints or only a subset of v0.
  • Rate limiting behavior and retry logic when making API calls.
  • Whether SSL verification can be disabled safely in production contexts beyond testing.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
requeststyping-extensions
MaintenanceActively maintained 8 days since the last release
Last repo commit
First released
Downloads238,203 / month, #8,944 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14

Evidence: socketdev-3.5.0-py3-none-any.whl

Tags

Capabilities
socket.dev api clientpython sdk socket securitysbom export pythonpackage vulnerability scanningsupply chain security apipurl package lookupcyclonedx spdx export
Topics
supply-chain-securitysbomapi-client
PyPI keywords
ossscasdksecuritysocket.devsocketsecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “socket.dev api client”

  • socketdevA Python SDK that wraps the Socket.dev REST API, enabling…
  • socketsecuritySocket Security CLI scans Python projects for supply-chain security…
  • codewords-clientA Python client library for the Codewords API with built-in FastAPI…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also socketsecurity · hiddenlayer-sdk · distro2sbom · lib4sbom · cyclonedx-py · harborapi · python-http-client · safety · cyclonedx-bom · pysnyk