
Sarah Gooding
@pollyplummer
Followers
11K
Following
4K
Media
274
Statuses
16K
Head of Content Marketing @socketsecurity (https://t.co/T0hRfvAzU0) Open source and open web advocate, runner, knitter. Also at https://t.co/kPAv4D4kxU
Saint Johns, FL
Joined April 2008
I'm excited to share that @SocketSecurity has raised $40M in Series B funding led by @AbstractVC! We're securing open source software at scale and have so much more to achieve on our mission. A big thank you to the 1M+ developers who trust our platform to secure your code!.
🚀 We’re thrilled to announce Socket’s $40M Series B led by @AbstractVC with participation from @eladgil and @a16z!
1
4
11
RT @foundmyfitness: I increase my creatine dose to 20 grams when I'm under-slept or jet-lagged. I've definitely noticed a boost in mental….
0
153
0
Big news for Rust devs! 🦀 Socket now supports Rust and Cargo! cc: @ThisWeekInRust.
🚀 Day 4 of Launch Week: Introducing Rust support in Socket!. Search any crate on — no login required. Enterprise users get early access to experimental SBOM generation & full supply chain protection. 🦀 More Details → #RustLang
0
0
3
What’s an OSS Vulnerability Janitor? by @JLLeitschuh
infosecwriteups.com
What does it take to sweep up after the industries security vulnerabilities that have been left unpatched or undisclosed?
0
0
1
RT @SocketSecurity: ⚡️ Results are precomputed & cached for popular dependencies, so they're available immediately. 🧘♀️ No additional sca….
socket.dev
Socket’s precomputed reachability slashes false positives by flagging up to 80% of vulnerabilities as irrelevant, with no setup and instant results.
0
3
0
RT @SocketSecurity: 🚀 Day 3 of Socket Launch Week: We’re launching Precomputed Reachability Analysis! . Socket takes a radically different….
0
3
0
✨ A little bit of behind the scenes from the @SocketSecurity story: @feross explains the importance of focusing on getting users, revenue, and adoption while building a company that works.
@feross Aboukhadijeh, Founder and CEO of @SocketSecurity (socket. dev) explains the importance of achieving traction / PMF, and actively sharing success, instead of focusing too much on fundraising.
1
2
3
Browser extensions can turn malicious overnight through silent updates, even those with verified badges and thousands of installs. Big news today: Socket is tackling this with our experimental Chrome extension scanning. Get in touch if you want to be part of our pilot program.
Day 2 of Socket Launch Week: DOUBLE LAUNCH 🚀.Browser extensions are a growing attack surface for nearly every organization. Today, we’re launching an experimental release of Chrome extension scanning to detect malware and risky updates. 🧩 Learn more →
0
1
5
💥 Socket is now available on Claude Desktop!. Add secure dependency scanning with Socket MCP, a new one-click extension.
🚀 Day 2 of Socket Launch Week: Introducing Socket MCP for Claude Desktop!. Add one-click dependency security scanning to your Claude conversations. No CLI, no configuration files: just install and ask #Claude to check your dependencies. Try it now →
0
1
4
RT @charliermarsh: uv continues to grow at an absolutely ridiculous rate. uv users are making over half a BILLION requests per day. Up 40%….
0
29
0
RT @bryanfcasey: And you thought you knew sophisticated ways to build community around open source projects.
0
2
0
RT @robpalmer2: TypeScript excitement 😉. TS 5.9 RC is out 🎉. 🔶 `import defer` by @NicoloRibaudo.🔶 module: "node20" for require(ESM).🔷 --ini….
0
27
0
If you believe AI's growing pains are just the prelude to an unstoppable wave of progress, this podcast episode is gonna be your vibe. Listen to @feross and @a16z's Joel de la Garza discuss AI security, vibe coding, and the future of the software supply chain.
Vibe coding with LLMs is making developers faster, but also creating new attack surfaces. Socket CEO @feross talks with Joel de la Garza of @a16z about the future of AI-assisted software and supply chain security. 🎙️Check out the full episode:
1
2
3
RT @SocketSecurity: 🚨 New Threat Research: We uncovered 4 malicious packages (3 on npm, 1 on PyPI) with 56,000+ downloads, all delivering s….
socket.dev
Socket researchers investigate 4 malicious npm and PyPI packages with 56,000+ downloads that install surveillance malware.
0
3
0
Y’all, it’s nonstop. Hopefully you have a tool like Socket in place to check your dependency updates. By the way, our Team plan is FREE for open source projects. Maintainers, get in touch and we'll hook you up. 💜 #oss.
🚨 Supply chain attack alert: A threat actor gained access to @toptal’s GitHub org, making 73 repos public and injecting malicious payloads into 10+ npm packages. Full research: #NodeJS #JavaScript.
1
2
2
RT @david_perell: It seems like there’s an overwhelming amount of good content on the Internet, but every time somebody publishes something….
0
11
0
RT @SocketSecurity: 🚨 Attackers have hijacked the npm 'is' package (~2.8M weekly downloads), adding a malicious JS loader. This compromise….
socket.dev
The ongoing npm phishing campaign escalates as attackers hijack the popular 'is' package, embedding malware in multiple versions.
0
6
0
RT @SocketSecurity: 🚨 A critical vulnerability in the widely used npm form-data package could allow HTTP Parameter Pollution, potentially i….
socket.dev
A critical flaw in the popular npm form-data package could allow HTTP parameter pollution, affecting millions of projects until patched versions are a...
0
1
0
RT @SocketSecurity: Bun 1.2.19 introduces isolated installs for monorepos, smarter package management, and 5x faster Bun.sql. 🎉 Congrats to….
socket.dev
Bun 1.2.19 introduces isolated installs for smoother monorepo workflows, along with performance boosts, new tooling, and key compatibility fixes.
0
12
0