Overview
Socket.dev detects malicious and risky open source packages before they enter your codebase. The Pwnbook integration pulls supply chain alerts from Socket so your team can review and act on package-level risks in context.Prerequisites
- A Socket.dev account
- A Socket API key
- Admin or Owner access in Pwnbook
Setup
1
Get your Socket API key
- Log in to socket.dev.
- Go to Settings → API Keys.
- Create a new key and copy it.
2
Configure in Pwnbook
- Go to Organization Settings → Marketplace → Socket.dev.
- Enter your API Key and select the organizations to monitor.
- Click Save & Test.