nowfound

Alternatives

Products that do what Socket for GitHub 1.0 does

Secure your JavaScript supply chain – block malware packages

  1. 1
    Socket211

    Secure your JavaScript supply chain

    2022

  2. 2
    Arnica97

    Behavior based software supply chain security

    2022

  3. 3

    Bring confidence and security to your Web3 transactions

    2024

  4. 4

    Open sourced application to detect security vulnerabilities.

    2020

  5. 5
    RustScan108

    Fast and developer-friendly Rust contract security scanner

    2025

  6. 6
    Trace-AI146

    Know What You Ship. Secure What You Depend On.

    Oct 2025

  7. 7
    hop.js129

    A fast, free, privacy-first CDN for open-source projects

    Oct 2025

  8. 8

    Fraud and theft protection for cryptocurrency

    2018

  9. 9DI
  10. 10

    Free enterprise grade security for your personal browser

    2023

  11. 11

    Protect yourself from crypto scams and frauds

    2018

  12. 12

    Secure cryptocurrency trading directly from your wallet

    2018

  13. 13AG
  14. 14VN

    If you are worried about the recent Lazarus group software supply chain attack, you should consider having guard rails that is more than conventional SCA. `vet` detects the package (version) published in the report as malware. Try out vet, its free and open source: https://github.com/safedep/vet More details on the attack: https://www.nodejs-security.com/blog/north-korea-malware-on-...

    2023 · github.com

  15. 15SJ
  16. 16TS

    Hi HN, I’m Guillaume, the cofounder of Bearer, an Open Source SAST solution. After launching a few weeks ago here on Hacker News with support for Ruby and JavaScript stacks, I’m happy to report we’ve just released a new version (v1.2) with TypeScript support! In terms of code coverage, we use the same rules already implemented for vanilla JavaScript, but as usual, you can build your own. The rules list is here: https://docs.bearer.com/reference/rules/ It’s a first version for TS, but we believe that thanks to the pre-existing JavaScript support it should already…

    2023

  17. 17MA
  18. 18PI

    People seem to be blindly hooking up their OpenClaw’s to their personal data. So, I built runtime controls to prevent at the least, very simple prompt injection attacks. Once installed, it hooks to Node.js child_process module in the gateway process and listens to tool calls and their response streams. And a fetch hook to monitor user prompts (both could’ve been through fetch, happy to discuss why this whole layer couldn’t just be a proxy). There are two layers of protection: First: Whenever there is a read-only tool call whose response an attacker can modify, we extract that part of the…

    Feb 2026 · github.com

  19. 19

    Proves vulnerabilities before reporting them.

    8d ago · dashboard-seven-self-13.vercel.app

  20. 20RA
  21. 21UB

    2014 · bitcoinvigil.com

  22. 22RA

    I've been building Rivers for the past 7 months, an asset-based orchestrator. The core components such as planning, scheduling etc are in Rust and the user facing API is in Python. My most recent release adds OIDC and forward auth support. Security shouldn't be paywalled :)

    Jul 2026 · github.com

  23. 23SE
  24. 24IB

    Logging and tools like Sentry are a thing of the past. A while back on a night out in northern Norway, I had to start debugging a critical production bug that broke the payment flow of my SaaS product. I had limited time to fix the bug or I would have lost about ~1K profit. Super stressful. I had logging and Sentry in place, but neither helped me reproduce or find the root cause of the bug. Ever since, I started thinking; why can’t we just have a tool that you setup once, and that allows us to reproduce every function call and function that the user ran before the bug? This is how the idea…

    2023 · useflytrap.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →