# Socket Blog

The blog of [Socket](https://socket.dev/), the supply-chain-security company that scans package registries (npm, PyPI, RubyGems, Maven, Go modules) for malicious packages. The blog publishes timely writeups of registry incidents, maintainer disputes, and ecosystem-level security analyses — typically faster than other security press for npm-side incidents because Socket's scanners are usually first to detect.

URL: <https://socket.dev/blog>

Why tracked: Socket is one of three or four outlets (alongside StepSecurity, Phylum, Snyk) that publishes detailed postmortems on supply-chain incidents in time to be useful. Articles tend to be focused, with screenshots from the originating GitHub issues and primary-source quotes.

## Ingested articles

- [[fsnotify-maintainer-dispute]] — the fsnotify maintainer-access dispute, May 2026

## See also

- [[supply-chain-security]]
