HarperFast / HarperFast/harper
Investigate Socket.dev for supply chain attack scanning
- Dominant language
- JavaScript
- Stars
- 89
- Forks
- 10
- Avg merge
- 2d 2h
- Merged PRs (30d)
- 205
Description
As supply chain attacks grow more dangerous, integrate [Socket](https://socket.dev/) (or similar) for scanning npm dependencies for known-malicious or supply-chain-compromised packages — beyond what Renovate/npm audit covers.
## Ask
- Evaluate Socket.dev GitHub app or equivalent CI integration on `harper` and `harper-pro`.
- If viable, enable it and address any immediate findings.
- Document the scanning coverage alongside the existing Renovate + `npm-shrinkwrap.json` + `package-lock.json` posture.
---
Jira fields: **Feature Type:** Security · **Business Impact:** Operational efficiency
🤖 Filed by Claude on behalf of Kris.
Contributor guide
Research direction
Start by reviewing the existing Renovate setup and npm-shrinkwrap.json and package-lock.json files for harper and harper-pro, then evaluate the Socket.dev GitHub app or an equivalent CI integration. Done means a viable scanner is enabled if appropriate, immediate findings are addressed, and the scanning coverage is documented alongside the existing dependency posture.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, nodejs
- Domain
- ci-cd, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100