August 25
Socket now supports creating and managing Asana tasks from alerts. Tasks can be created manually or through ticketing rules that filter by event, type, priority, repository, or other attributes; select the Asana workspace, project, tags, and assignee; and configure how the linked task and alert update as their status changes.
The integration is available in beta on Business and Enterprise plans. Read the announcement and documentation.

August 21
PHP and Composer support has moved from Experimental to Beta and is now available for all Socket users. PHP reachability analysis is now generally available for customers on Team plans and higher and no longer requires Experimental access.
Read the announcement, and check out the documentation for precomputed reachability and full application reachability.
August 20

Socket now scans every Firefox extension listed in Mozilla’s official add-ons directory and monitors new releases for changes in permissions, code, network activity, and behavior. Analysis covers extension metadata, active sites, package files, network endpoints, malware, credential and clipboard theft, data exfiltration, remote loading, obfuscation, impersonation, and related campaign activity.
Firefox coverage is available in Experimental for Enterprise customers. Contact your Socket account team to enable it, and read the announcement for more details.
July 10
Socket now correctly scans crates.io package versions that have been yanked but remain pinned in a project’s Cargo.lock, preventing failures for projects that still depend on archived crate versions.
July 9
Repository-scoped API tokens can now retrieve the supported-files list required to start reachability scans. This fixes an issue where scans authenticated with a repository-scoped token could fail with a 403 error before analysis began, making it easier to use least-privilege credentials with the Socket API.
July 6
Packagist package pages now show the full commit history for tags that have been force-pushed, with the commit currently associated with the tag highlighted. This makes it easier to identify when a published package version has been retagged and review the commits it previously referenced.
July 3
Full scan metadata responses now consistently include the repository, workspace, report URL, API URL, and scan type fields documented in the API contract.
July 3
Private packages that Socket cannot score now display N/A instead of a numeric score in pull request comments and dependency views. This prevents private packages from appearing to have passed or failed analysis when no score is available.
July 2
Fixed an issue where pull request detail pages could return a "Not Found" error after a workspace was renamed, even though the pull request still appeared in the list. Existing pull request links now continue to work after workspace renames without requiring any additional action.
June 30
Organizations can now opt in to include AI-generated reachability specifications alongside human-verified ones, giving more vulnerabilities a reachability verdict.
This setting can be enabled under Settings → Alert Scans → Reachability. Once enabled, it applies across reachability analysis and broadens coverage, with a slightly higher risk of an incorrect result.
Alert details now include a Specification field that shows whether a reachability result came from an AI-generated or human-verified specification.
