Off the Bit
Tools: Socket
Category: Security and secrets
Site: socket.dev
Socket
Supply chain security that inspects what a dependency actually does, rather than only checking it against a vulnerability list. The site refused an automated request.
Reads the package's behaviour, not just its version.
This one did not answer. Asked on 2026-09-04, and
the site refused an automated request. The entry stays because nothing here is deleted, and because a tool
that has gone is worth knowing about. The link above is not live.
What it is sold for
Blocking malicious dependencies before they install.
Same shelf
The rest of security and secrets, alphabetically. Sharing a category is a filing decision, not a relationship.
- Fine-grained authorization as a service, so permission checks stop being scattered if-statements.
- Hosted identity: login, federation, multi-factor and the standards work nobody wants to implement twice.
- Amazon's managed identity for consumer applications, priced and scaled for very large user pools.
- Static analysis for security and privacy risk, focused on where sensitive data flows. Acquired by Cycode.
- The open-source scanner behind Bearer. Finds and ranks security and privacy risk in source, and still runs on its own.
- Open-source SAML and OIDC single sign-on, so enterprise login is not a rewrite. The address now serves Ory.
- Enterprise application security, combining several scan types and consolidating findings into one risk view.
- Authentication with the interface components included, built for React and Next.js first.
ImranTools[Socket]