Apply security fixes to the dependency versions your project already uses. Socket provides patches for specific package versions so you can address known vulnerabilities without waiting for an upstream release or upgrading the dependency.
The default workflow is scan → install → vex:
socket-patch scanfinds available patches and updates your dependency files to use Socket-hosted patched packages.- Your package manager installs those packages using the updated references and
integrity pins. Commit the files that
scanreports. socket-patch vexproduces an OpenVEX document describing the vulnerabilities addressed by those patches.
Use socket-patch vendor to put the selected patched packages in your repository
when installs must work without Socket's patch server.
This branch documents the v5 prerelease. Installation commands below select the latest published release, which may have different behavior. To try this branch, build from source. Existing users should read the v5 migration guide.
Install a standalone binary on macOS or Linux:
curl -fsSL https://install.socket.dev/patch | shThe installer verifies the download against the release's SHA256SUMS and installs
in /usr/local/bin or ~/.local/bin. To choose a directory or release, pass
SOCKET_PATCH_INSTALL_DIR or SOCKET_PATCH_VERSION to sh after the pipe.
See the installer source and
mirror configuration.
On Windows, extract a socket-patch-*-pc-windows-msvc.zip archive from
GitHub Releases into a directory
on your PATH, or install through npm:
npm install -g @socketsecurity/socket-patchCargo users can build and install the published CLI with
cargo install socket-patch-cli. All distributions support the same ecosystems;
you do not need Node.js or Rust to use the standalone binary.
For standalone installs, run socket-patch --update to update. For npm or Cargo
installs, use that package manager's update command. The
platform matrix lists release targets.
From the root of a project with dependency files:
socket-patch scan --dry-run # preview available patches and edits
socket-patch scan # apply hosted references; never promptsWithout an API token, the CLI uses Socket's public proxy for free patches.
To use your organization's patch tier, set SOCKET_API_TOKEN, or sign in with the
separate Socket CLI using socket login. See configuration.
A scan with no available patches means the catalog has no applicable patch for this run. It is not a finding that the project has no vulnerabilities.
Review and commit the files the scan changed. Hosted mode keeps no patch ledger;
its state is in the project's lockfiles, manifests, and package-manager configuration.
For example, an npm project may change both package-lock.json and .npmrc:
git diff
git add package-lock.json .npmrc
git commit -m "Apply Socket security patches"
npm ci
socket-patch vex --output socket.vex.json
socket-patch listUse your project's normal install command in place of npm ci. Some package
managers reuse installed or cached upstream packages; follow any reinstall warning
from the CLI and the ecosystem notes. Generate VEX after
installing to verify the copies your build consumes, then pass the document to your
VEX-aware vulnerability scanner.
| Mode | Command | What to commit | What installs need |
|---|---|---|---|
| Hosted (default) | socket-patch scan |
Changed lockfiles, manifests, and registry configuration | Access to Socket's patch server |
| Vendored | socket-patch scan --mode vendored |
Changed dependency files and .socket/vendor/ (artifacts and ledger) |
The committed patched packages |
| Agent | socket-patch scan --mode agent |
.socket/manifest.json and patch data; Go also uses a committed patched tree |
socket-patch apply after dependency installs |
Vendored mode stores patched dependencies, not the entire dependency graph. Other dependencies still need their normal registry, mirror, or offline cache. Hosted and vendored installs do not need an install hook or the Socket Patch CLI.
The CLI supports npm, PyPI, Cargo, Go, RubyGems, Maven, Composer, NuGet, and Deno. Mode and package-manager support vary: Deno uses agent mode, for example. Check the ecosystem support matrix before choosing a mode.
Vendored Maven reactors and Gradle 6.8+ builds are supported. See JVM vendoring for supported project shapes, cache behavior, and offline checks.
socket-patch scan --package lodash # limit selection to a package
socket-patch scan --max-new-patches 5 # introduce at most five new patches
socket-patch scan 'apps/*' # scan project directories in a monorepo
socket-patch get CVE-2024-12345 # target an advisory; hosted by default
socket-patch vendor # eject an existing hosted patch set
socket-patch rollback # restore upstream dependenciesget also accepts a GHSA, patch UUID, PURL, or package name. scan selects from
patches your account can download, preferring the highest severity, then the most
advisories fixed, then the newest publication date. Existing patches are upgraded
only by a better-ranked patch.
Hosted rollback resolves upstream metadata and generally needs network access.
Where restoration is unsupported, including hosted binary bun.lockb, the CLI
refuses the change and gives a version-control recovery hint. See
usage and recovery.
Use socket-patch <command> --help for options and
socket.yml for a shared rollout policy.
- Usage: targeting, CI, vendoring, agent mode, VEX, and recovery.
- Configuration: authentication, environment, and rollout policy.
- Ecosystem support: package-manager formats and limitations.
- Migrating to v5: changed defaults and retired install hooks.
- CLI contract: flags, JSON, diagnostics, and exit codes.
- Development: code map, builds, and test entry points.
- Release runbook and changelog.