$npx skillfedfor your agent

socketsecurity

Socket Security CLI for CI/CD

With conditionsPyPI Quality AssuranceReleased Aug 2026220.6K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — socketsecurity-2.6.4-py3-none-any.whl
v2.6.4 · released 2026-08-12 · Python >=3.11 · 11 runtime deps: beautifulsoup4, brotli, brotlicffi, gitpython, markdown, mdutils, packaging, prettytable

Yes, if you need supply-chain security scanning in CI/CD. The tool is actively maintained, has low install friction, and integrates well with common platforms (GitHub, GitLab, Buildkite, Bitbucket). Requires Python 3.11+ and a Socket Security API token. No known vulnerabilities. MIT license is permissive. Start with a basic policy scan or SARIF export to evaluate fit.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.11 or later and a valid Socket Security API token set via SOCKET_SECURITY_API_TOKEN environment variable.
  • Low install friction with a pure-Python wheel.
  • Active maintenance with a release 2 days old.

License · maintenance · safety

permissive license (permissive) — MIT License permits free use, modification, and redistribution with minimal restrictions—suitable for both open-source and commercial projects.

last release 2026-08-12 (2 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 220,640 downloads/mo, #9,295 on PyPI

Verify before relying

pip install socketsecurity
export SOCKET_SECURITY_API_TOKEN="your-token"
socketcli --target-path .
  • Whether the CLI's exit codes (0, 1, 2, 3) and blocking behavior match your CI/CD platform's expectations.
  • Whether the package's reachability analysis covers all dependency types in your project (transitive, optional, dev).
  • Whether SARIF output is compatible with your security scanning dashboard or SIEM integration.
Same gist for agents: .md · .json

What it is and what it does

Socket Security CLI is a command-line tool that scans Python projects for supply-chain security issues—vulnerabilities, policy violations, and license risks—and reports results in multiple formats. It integrates directly into CI/CD pipelines to gate deployments based on security findings, with support for diff-based PR scanning, full-scope analysis, and reachability-aware filtering to reduce noise.

The tool connects to Socket's backend service via API token and can export findings as SARIF (for GitHub, GitLab, and other platforms), JSON reports, SBOMs, and legal/compliance artifacts. It supports both simple policy enforcement (exit on blocking issues) and detailed investigation workflows (full-scope SARIF with instance-level detail). Configuration is flexible—via CLI flags, environment variables, or TOML/JSON config files—and includes presets for common scenarios like legal compliance and FOSSA compatibility.

Use it for

  • Gate pull requests in CI/CD by scanning diffs against a baseline commit and blocking merges if new security issues are found.
  • Generate SARIF reports for GitHub Advanced Security, GitLab Dependency Scanning, or other security dashboards.
  • Export legal/compliance artifacts (SBOM, license inventory) in standard or FOSSA-compatible formats for audit trails.
  • Analyze reachability of vulnerabilities to prioritize fixes based on whether issues are actually used in your code.
  • Enforce supply-chain security policies across teams by running scans on every commit to the default branch.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need supply-chain security scanning in CI/CD.

The tool is actively maintained, has low install friction, and integrates well with common platforms (GitHub, GitLab, Buildkite, Bitbucket). Requires Python 3.11+ and a Socket Security API token. No known vulnerabilities. MIT license is permissive. Start with a basic policy scan or SARIF export to evaluate fit.

Install

socketsecurity on PyPI

Before you install

Low install friction with a pure-Python wheel. Active maintenance with a release 2 days old. Requires Python 3.11 or later and 11 runtime dependencies including requests, beautifulsoup4, and gitpython.

Requires Python 3.11 or later and a valid Socket Security API token set via SOCKET_SECURITY_API_TOKEN environment variable.

License in practice

MIT License permits free use, modification, and redistribution with minimal restrictions—suitable for both open-source and commercial projects.

Quickstart

pip install socketsecurity
export SOCKET_SECURITY_API_TOKEN="your-token"
socketcli --target-path .

Verify before relying

  • Whether the CLI's exit codes (0, 1, 2, 3) and blocking behavior match your CI/CD platform's expectations.
  • Whether the package's reachability analysis covers all dependency types in your project (transitive, optional, dev).
  • Whether SARIF output is compatible with your security scanning dashboard or SIEM integration.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.11
Install frictionLow. Pure-Python wheel
Runtime dependencies
11 packages
beautifulsoup4brotlibrotlicffigitpythonmarkdownmdutilspackagingprettytablepython-dotenvrequestssocketdev
MaintenanceActively maintained 2 days since the last release
First released
Downloads220,640 / month, #9,295 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersProgramming Language :: Python :: 3.11Programming Language :: Python :: 3.12

Evidence: socketsecurity-2.6.4-py3-none-any.whl

Tags

Capabilities
python supply chain security scanningdependency vulnerability scanning clisarif security report generationci/cd security policy enforcementsoftware composition analysisreachability analysis securitygitlab security scanning integration
Topics
supply-chain-securityci-cd-integrationsarif-export
PyPI keywords
ossscasecuritysocket.devsocketsecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ci/cd security policy enforcement”

  • socketsecuritySocket Security CLI scans Python projects for supply-chain security…
  • semgrepSemgrep is a static analysis tool that searches source code for bugs,…
  • c7nCloud Custodian is a rules engine that enforces cloud infrastructure…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also ca9 · socketdev · pysentry-rs · guarddog · safety · bridgecrew · cisco-ai-skill-scanner · sarif-tools · truffleHog · ci-info