Socket Blog
- title
- Socket Blog
- type
- entity
- summary
- Socket.dev's writeups of npm/PyPI/RubyGems supply-chain incidents and ecosystem-security analysis
- tags
- blog, security, supply-chain
- sources
- fsnotify-maintainer-dispute
- created
- 2026-05-12
- updated
- 2026-05-12
The blog of Socket, the supply-chain-security company that scans package registries (npm, PyPI, RubyGems, Maven, Go modules) for malicious packages. The blog publishes timely writeups of registry incidents, maintainer disputes, and ecosystem-level security analyses โ typically faster than other security press for npm-side incidents because Socket's scanners are usually first to detect.
Why tracked: Socket is one of three or four outlets (alongside StepSecurity, Phylum, Snyk) that publishes detailed postmortems on supply-chain incidents in time to be useful. Articles tend to be focused, with screenshots from the originating GitHub issues and primary-source quotes.
Ingested articles
- fsnotify-maintainer-dispute โ the fsnotify maintainer-access dispute, May 2026
See also
Linked from