# "Supply Chain" security for developers

**URL:** <https://discourse.nodered.org/t/supply-chain-security-for-developers/99531>\
**Category:** Developing Nodes\
**Tags:** security\
**Created:** [29 October 2025 14:00 UTC](https://discourse.nodered.org/t/supply-chain-security-for-developers/99531 "2025-10-29T14:00:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [29 October 2025 14:00 UTC](https://discourse.nodered.org/t/supply-chain-security-for-developers/99531/1 "2025-10-29T14:00:41Z")

</div>

With recent widespread attacks on the open source community, though I would share some additional security tooling that is free, easy to use and will help node.js, Python, etc developers against supply chain attacks.

In other works prevent your software update accidentally and unknowingly incorporating malware from dependencies.

The security vendor "Socket" (not to be confused with _[Socket.IO](http://Socket.IO)_) already provides some tools that will [check your PR's for supply chain issues](https://www.theregister.com/2022/03/01/socket_npm_dependency_scanner/), or that you can [run on the command line when using `npm`](https://www.theregister.com/2023/03/16/socket_npm_safe_javascript/).

But now they have provided a further tool that prevents compromised dependencies even reaching your computer and that will work with other library management tools including for Python and Rust.

> **[GitHub - SocketDev/sfw-free: Wraps your package manager, preventing...](https://github.com/SocketDev/sfw-free)**
>
> Wraps your package manager, preventing installation of malicious packages.

I strongly encourage all developers to adopt these tools and others that help protect everyone from the rapidly increasing global malware war that is now taking place.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [28 December 2025 14:00 UTC](https://discourse.nodered.org/t/supply-chain-security-for-developers/99531/2 "2025-12-28T14:00:56Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
