SocketDev / SocketDev/socket-basics
Core tool version drift detected
Open
Nobody has claimed this yet.
core-tool-drift
- Dominant language
- Python
- Stars
- 14
- Forks
- 8
- Avg merge
- 2d 21h
- Merged PRs (30d)
- 13
Description
Core tool supply-chain watch
| Tool | Pinned | Latest | Drift | Socket (pinned) | Socket (latest) |
|---|---|---|---|---|---|
| OpenGrep (SAST engine) | v1.26.0 |
v1.30.0 |
⬆️ v1.30.0 |
✅ clean (629 alerts) | ❓ coordinate not resolvable |
| TruffleHog (secret scanner) | 3.96.0 |
v3.97.5 |
⬆️ v3.97.5 |
✅ clean (17 alerts) | ✅ clean (22 alerts) |
| Trivy (Socket trivy-dist) | 0.73.0 |
0.73.0 |
✅ current | ✅ clean (21 alerts) | ✅ clean (21 alerts) |
| Socket SDK (socket-sdk-python) | 3.6.0 |
3.6.0 |
✅ current | ✅ clean (5 alerts) | ✅ clean (5 alerts) |
| Socket Python CLI (socket-python-cli) | 2.9.0 |
2.9.4 |
⬆️ 2.9.4 |
✅ clean (4 alerts) | ✅ clean (6 alerts) |
| Socket npm CLI (socket-cli) | 1.1.165 |
1.1.176 |
⬆️ 1.1.176 |
✅ clean (3 alerts) | ✅ clean (3 alerts) |
Notes
- OpenGrep (SAST engine): GitHub-release binary; not Dependabot-trackable and not covered by Socket's pkg:github coordinates. Falls back to the upstream Semgrep lineage (pkg:pypi/semgrep) as a project-health proxy -- this does NOT analyze OpenGrep's own release artifacts, so it is reported, never build-failing.
- Trivy (Socket trivy-dist): Release drift follows the Socket-built ghcr.io/socketdev/trivy package (produced by SocketDev/trivy-dist and mirrored privately to Docker Hub), not Aqua's release feed. Socket scoring uses the corresponding upstream Go module because trivy-dist rebuilds that source without modification.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files or tests are named. Search the repository for the pinned versions listed in the table, then inspect the workflow or entry point that runs OpenGrep, TruffleHog, Trivy, and the Socket CLIs. Done means supported drift is updated and the existing scan checks pass, while OpenGrep's unresolved latest coordinate remains report-only.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, python
- Domain
- devops, security, tooling
- Issue type
- Refactor
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 58/100