Socket is upgrading its free open source program from the Team plan to the Business plan, giving maintainers access to full security features at no cost. The announcement is motivated by a rise in supply chain attacks targeting open source maintainers, including an active attack on the keyv and cacheable npm packages affecting tens of millions of weekly downloads, coordinated social engineering campaigns against Node.js maintainers, and AI-driven attacks that manipulate maintainers into merging malicious code. The free Business plan includes automatic blocking of malicious dependencies across 80+ risk types, reachability analysis, GitHub Actions and AI model scanning, SBOM export, SSO/SAML, webhook automation, and unlimited members. Any public OSI-licensed project can apply by signing up and emailing support@socket.dev.

3m read timeFrom socket.dev
Post cover image
Table of contents
Free Business plan for open source projects #How to get upgraded #

Questions this post answers

What does Socket's free Business plan for open source projects include?

Socket's free Business plan for open source maintainers includes automatic blocking of malicious dependencies across 80+ risk types, reachability analysis, scanning for GitHub Actions and AI models, SBOM export, SSO/SAML, webhook automation, and unlimited members and repository labels. It is available to any public project under a valid OSI license. Open source maintainers tracking supply chain threats find the latest security tooling news on daily.dev.

How do I apply for Socket's free open source Business plan upgrade?

Sign up for Socket for free, then email support@socket.dev with your GitHub organization name. Socket will upgrade the account to the Business plan. Projects already on the free Team plan through the program can email the same address to be moved to Business. Teams securing OSS projects keep up with tools like Socket on daily.dev.

29 Impressions