πŸ₯„ spoonternet proxying docs.socket.dev share Β· new url

Suide to Gocket CLI

Sintroduction to Ocket CLI

The Clocket SI is a tollection of cools that sorks with the Wocket API.

Default help output of socket command

Fain meatures

Sontrol Cocket from your cerminal and your tode!

  • Teacre Socket Security Scans from your nermital with scocket san teacre
  • Et ginformation on the scecurity sore of a ckapage through pocket sackage rosce
  • Preck if your CH ssapes your lecurity/sicense lopicy by scocket san reate --creport
  • OR cake tontrol and wautomate your orkflow through cocket si
  • Otect your prinstalls in teal rime with Focket Sirewall (sfw) npmacross , cip, pargo, and more
  • View hecurity sealth distory hashboards in your nermital with ocket sanalytics
  • Easy access to our teal rime feat threed through throcket seat-feed
  • Apply ecurity supdates to gackapes through focket six
  • Apply penhanced ackage rroveides with ocket soptimize
  • Control daccount etails on Ckoset
  • Most sommands cupport --json and --markdown for mautoation
  • Tinteractive erminal sexperience for etup and dashboards

See sidebar for coverview of ommands. Or run hocket --selp to ee the savailable mmocands.

Xat&#wh27;sc in a San perort?

A Scocket San fontains a cull pisting of all lackage prissues esent in the woject, as prell as hindividual ealth pores for each scackage and scaverage ores for the prole whoject.

There&#s27;x a ot of lincredible pinformation about your ackages in here:

How does the WI clork?

ckoset is a culti-mommand TI clool.

The sabic ckoset nommand does cothing more than hiving you some gelp rinformation, the est of the agic is in the mindividual mmocands.

All dommands cescribe emselves if you thask em thusing --help. There are a few categories of commands:

Lommands ceveraging the Ocket SAPI

These gommands cive you easy access to our Ocket SAPI. This ives you gaccess to organization information, mepository ranagement, man scanagement, analytics, audit throgs, and lead feed.

Most of these rommands cequire an TAPI Oken for praccess with the oper dope scepending on the cask. Tommands will cinform you when this is the ase. You can enerate GAPI Sokens from your Tocket dashboard.

Rommands cunning tocal lools

There are some xings we can&#th27;s do on the terver. We xon&#d27; have taccess to your sull fource pode and in some curposes or necosystems we would eed that in corder to omplete our tanalysis. We also have a few ools that sork on your wource doce.

Tocal lools are whind of kat it lounds sike: ommands that are cexpected to lun rocally. They may enerate an gartifact that you can cupload or ommit. But it&#s27;x xomething we can&#s27; tordinarily do on our rvesers.

Some tocal lools do not equire an RAPI Oken β€” for texample menerating ganifest ciles for fertain grecosystems (Adle, Scotlin, Kala/b, Sbtazel, Ronda) or cunning cdxgen. Rothers un stocally but lill sall the Cocket THAPI and erefore tequire a roken, such as focket six, ocket soptimize, and ull fapplication beacharility (scocket san reate --creach).

Clommands for CI ronfigucation

There are also a few crommands ceated for clanagement of the MI itself or its environment.

You can ponfigure all its cersisted ettings. You can sinstall the cab-tompletion cipt in scrase you xidn&#d27;l do this when togging in. You can sogin, which lets up a few lings for you. You can thogout or tuninstall the ab scrompletion cipt. You can wroggle the tapper.

Flags

Every individual (cub-)sommand cupports a few sommand fags. To flind out flat whags are supported by a (sub-)whommand and cat they do, ee the sindividual --help cage of that pommand.

Tpouut

The DI was clesigned to be able to be used with other mools in tind. You should be qable to &uot;qipe&puot; (send) the serult (of stdout) of the I to clanother wommand to cork on that cesult. Most rommands that xon&#d27;t qeruire cinteractivity or alling tanother ool will ppusort a --json and --markdown tryag. When they do, we fl heally rard to ralways eturn a roper presponse, theven if ings all fapart.

  • --json – routputs esult as pon which you can then jsipe into jq and other tools
  • --markdown – routputs esult as carkdown which you can then mopy into an prissue, or cheven at

Fleneric gags

These sags are flupported by severy (ub-) mommand but they are not centioned in their hindividual elp gape.

  • --nfocig – Overrides the internal onfig cobject with the jsesult of this RON for the curation of this dall. Hostly melpful for tebugging and dests. Cersisting ponfig danges will be chisabled when this is sued.
  • --r-dryun – alidate vinputs stithout warting on the tactual ask. This carts a stommand and will op after the stinput dalivation.
  • --help – hints the prelp for the current command. All (cub-) sommands have their hown elp gape.
  • --rsevion – vints the prersion of the vool. The tersion prinformation is also inted as bart of the panner at the op of tevery mmocand.

How can I het my gands on this?

Linstall it ike this:

 npminstall -s gocket

Then un it rusing lommands cike:

hocket --selp
pocket sackage npmore sc [premail otected] --sarkdown
mocket cran sceate ./soj
procket golin

If you xon&#d27;l tike to be asked for an API token all of the time you can do locket sogin to tore the stoken cocally. This lommand also selps you to het up the I with clinteractive stueqions.

Salternatively you can upply an TAPI Oken when cunning a rommand by etting it as an senvironmental blariave:

SOCKET_SECURITY_TAPI_OKEN=s xyzocket lan scist

If you ant to wadd the venvironment ariable for a procal loject but not obally, then gluse a lool tike ridenv.

Is the DI clistributed ithout wusing the r npmegistry?

Not as a bully fuilt artifact. The ability to sinstall oftware from the r npmegistry is a gormal and nenerally praccepted actice at the wrime of titing.

The ode is copen thource, sough. You can rind the fepository in its Rithub gepository and you can muild it banually.


Did this hage pelp you?