SocketDev / SocketDev/socket-basics

Core tool version drift detected

Open
#93 14 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

core-tool-drift
Dominant language
Python
Stars
14
Forks
8
Avg merge
2d 21h
Merged PRs (30d)
13

Description

Core tool supply-chain watch

Tool Pinned Latest Drift Socket (pinned) Socket (latest)
OpenGrep (SAST engine) v1.26.0 v1.30.0 ⬆️ v1.30.0 ✅ clean (629 alerts) ❓ coordinate not resolvable
TruffleHog (secret scanner) 3.96.0 v3.97.5 ⬆️ v3.97.5 ✅ clean (17 alerts) ✅ clean (22 alerts)
Trivy (Socket trivy-dist) 0.73.0 0.73.0 ✅ current ✅ clean (21 alerts) ✅ clean (21 alerts)
Socket SDK (socket-sdk-python) 3.6.0 3.6.0 ✅ current ✅ clean (5 alerts) ✅ clean (5 alerts)
Socket Python CLI (socket-python-cli) 2.9.0 2.9.4 ⬆️ 2.9.4 ✅ clean (4 alerts) ✅ clean (6 alerts)
Socket npm CLI (socket-cli) 1.1.165 1.1.176 ⬆️ 1.1.176 ✅ clean (3 alerts) ✅ clean (3 alerts)
Notes
  • OpenGrep (SAST engine): GitHub-release binary; not Dependabot-trackable and not covered by Socket's pkg:github coordinates. Falls back to the upstream Semgrep lineage (pkg:pypi/semgrep) as a project-health proxy -- this does NOT analyze OpenGrep's own release artifacts, so it is reported, never build-failing.
  • Trivy (Socket trivy-dist): Release drift follows the Socket-built ghcr.io/socketdev/trivy package (produced by SocketDev/trivy-dist and mirrored privately to Docker Hub), not Aqua's release feed. Socket scoring uses the corresponding upstream Go module because trivy-dist rebuilds that source without modification.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files or tests are named. Search the repository for the pinned versions listed in the table, then inspect the workflow or entry point that runs OpenGrep, TruffleHog, Trivy, and the Socket CLIs. Done means supported drift is updated and the existing scan checks pass, while OpenGrep's unresolved latest coordinate remains report-only.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, python
Domain
devops, security, tooling
Issue type
Refactor
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.