So

Socket – Secure your JavaScript supply chain

Hacker News

Socket – Secure your JavaScript supply chain

Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the package code to characterize the package's behavior. This way, Socket can detect when packages use security-relevant platform capabilities, such as the network, filesystem, or shell. You can search for any npm package and see issues that've we've flagged for each package. We look for 70 issues (full list here: https://socket.dev/npm/issue ) and we put those into a Package Health score. See these examples: https://socket.dev/npm/package/left-pad https://socket.dev/npm/package/lodash Socket looks for indicators present in all of the recent npm supply chain attacks. We're proactively auditing every package on npm to flag these issues. Separately, we have a GitHub app that you can install. It detects typosquat attacks and leaves a comment on your pull request to let you know you might have installed the wrong package. We're currently working to enable it to leave comments for more of the package issues that we can detect, but we want to get the UX really good on that first, so we've released it and labeled it "beta". Happy to answer questions.

Share card

Actual performance

133points
42comments
Made the leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: new, code, open · Missing: mac, agents, macos
77%77% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Strong signals: para · Missing: supports, reddit linkedin, podcasting
73%73% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
Hacker NewsStrong engagement from HN community · Strong signals: excited, open source, filesystem · Missing: https docs, just released, exist
71%71% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
TrustMRRLess likely to generate early MRR · Strong signals: month, way, para · Missing: mobile apps, ios, personal
36%36% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Strong signals: platform · Missing: plus, intuitive, reviews
31%31% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Strong signals: active · Missing: arr, mrr, revenue
13%13% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

Li
Litterbox – Defend Against Supply Chain Attacks50%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Litterbox – Defend Against Supply Chain Attacks

Hacker News1
Centrum-Ai
Centrum-Ai42%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Supply Chain Resilience AI

Indie Hackerscommitment-full-time
ChainTraced
ChainTraced23%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Modernising supply-chain traceability and quality assurance

Indie Hackers
FineLine Technologies
FineLine Technologies46%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Supply Chain

Indie Hackerscommitment-full-time
Ch
ChainCentral – AI supply chain planning tool24%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

ChainCentral – AI supply chain planning tool

Hacker News1
Provenant Supply Chain Collaboration
Provenant Supply Chain Collaboration24%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Manufacturing supply chain visibility, fast.

Product Hunt+10
Vi
Visualize your software supply chain53%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Visualize your software supply chain

Hacker News4
Vi
Vigilance – Catch software supply chain attacks anywhere in the SDLC44%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Vigilance – Catch software supply chain attacks anywhere in the SDLC

Hacker News1
Craftifact
Craftifact44%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

EU artifact repository SaaS for secure software supply chain

Indie Hackerscommitment-side-project
Ne
New NPM Supply chain Attack?40%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

New NPM Supply chain Attack?

Hacker News2