Turn emails into revenue with Brew. No credit card, free credits to try.
socket.dev · newsletter
Explore this email design and adapt it to your own brand. Review the copy, links, and offer before sending.
socket-weekly-header
Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.
TOP STORY
pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies
pnpm 11 tightens JavaScript supply chain security defaults. Minimum Release Age was already available as an opt-in setting, but pnpm 11 makes 24 hours the default, alongside blocking exotic subdependencies and a new Allow Builds model for controlling dependency build scripts. The new defaults target exactly the conditions that make modern package compromises move fast: newly published malicious versions, install-time execution, and hidden dependency sources. Package managers are increasingly where supply chain security decisions get enforced, and pnpm 11 is one example of how they're responding to the nonstop stream of attacks on the ecosystem.
MORE NEWS
Critical vm2 Sandbox Escape Lets Untrusted JavaScript Run OS Commands
A critical sandbox escape in vm2 (CVE-2026-26956) lets attacker-controlled JavaScript break isolation, access the host Node.js process, and run arbitrary OS commands. Our testing found the issue affects 66 vm2 releases, broader than the advisory's listed range, and a free Certified Patch is available for teams that can't immediately upgrade.
fsnotify Maintainer Dispute Sparks Supply Chain Concerns
A maintainer access dispute in fsnotify, a Go library used by 321k projects for cross-platform file notifications, raised supply chain concerns this week after contributors were removed from the GitHub org and a deleted X post fueled takeover speculation. Although no code was compromised, governance ambiguity in this low-level dependency was enough to send users checking release history, watching forks, and asking whether routine updates were still safe.
MORE WORTH READING
OpenJS Foundation Security Update: Q1 2026
5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer
Behind the Scenes Hardening Firefox with Claude Mythos Preview
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access
Scaling Trusted Access for Cyber with GPT‑5.5 and GPT‑5.5‑Cyber
X
512x512-logo-27148
bluesky
Socket Inc.
Secure your supply chain. Ship with confidence.
2810 N Church St., Suite 71517, Wilmington,DE, 19802
Book a Demo • Unsubscribe