HarperFast / HarperFast/harper

Investigate Socket.dev for supply chain attack scanning

Open
#666 0 comments 0 reactions 0 assignees View on GitHub
area:security enhancement from-jira
Dominant language
JavaScript
Stars
89
Forks
10
Avg merge
2d 2h
Merged PRs (30d)
205

Description

As supply chain attacks grow more dangerous, integrate [Socket](https://socket.dev/) (or similar) for scanning npm dependencies for known-malicious or supply-chain-compromised packages — beyond what Renovate/npm audit covers.

## Ask

- Evaluate Socket.dev GitHub app or equivalent CI integration on `harper` and `harper-pro`.
- If viable, enable it and address any immediate findings.
- Document the scanning coverage alongside the existing Renovate + `npm-shrinkwrap.json` + `package-lock.json` posture.

---

Jira fields: **Feature Type:** Security · **Business Impact:** Operational efficiency

🤖 Filed by Claude on behalf of Kris.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the existing Renovate setup and npm-shrinkwrap.json and package-lock.json files for harper and harper-pro, then evaluate the Socket.dev GitHub app or an equivalent CI integration. Done means a viable scanner is enabled if appropriate, immediate findings are addressed, and the scanning coverage is documented alongside the existing dependency posture.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, nodejs
Domain
ci-cd, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.