SocketDev / SocketDev/socket-vscode

Unclear if setup is complete or broken

Open
#43 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
TypeScript
Stars
30
Forks
14
PR merge metrics
No merged PRs in 30d

Description

Thanks guys, this will be a really useful extension if I can get it to work.

It feels like there are some details missing from the extension docs or the socket.dev page:

  • Detailed install steps
  • What settings are required (if any)
  • Is the extension functionally dependent on payed tiers (I assume not as it states it works without the api)
  • What should users expect so see in the ui for different package scores

Steps to repro:

  • Create free tier account on socket.dev
  • Create an api key as per docs
  • Install the VS Code extension
  • Restart VS Code
  • Connect to the socket.dev api with the key
  • confirm [info] Socket Security extension started
  • Open my project package.json

Expected

A warning and overlay of dependencies that pose risk as per docs at https://docs.socket.dev/docs/socket-for-vs-code

Actual

No warning on obviously out of date dependencies. Only a score shown on hover of dependency, e.g.

Image

Env

  • MacOS 15.7
  • VS Code 1.104.2
  • socketsecurity.vscode-socket-security 2.0.3

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by following the setup steps in the issue and the linked Socket for VS Code documentation on macOS with VS Code 1.104.2 and extension 2.0.3. Compare the observed hover score with the documented warning and dependency overlay behavior; the work is done when the expected behavior or the setup requirements are clearly established.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript, vscode
Domain
devtools, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.