Back to Feed
Supply ChainJun 16, 2026

Introducing Manifest Alerts

Socket introduces Manifest Alerts to detect missing lockfiles and supply chain risks.

Vendor Watch

Run Manifest Alerts?

Get an email when a reviewed story names Manifest Alerts, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Socket has launched Manifest Alerts, a new feature designed to identify supply chain risks stemming from missing lockfiles in project manifests. This addresses the complexities of dependency resolution, as seen in the Axios npm compromise, where the impact was wider than initially apparent due to unpinned dependency trees. Manifest Alerts highlight projects where dependency installs are not reproducible, offering guidance for generating lockfiles across various package managers.

Full text

ProductIntroducing Reachability for PHPReachability analysis for PHP is now available in experimental, helping teams identify which vulnerabilities are actually exploitable. By Benjamin Barslev - Apr 24, 2026

Entities

Manifest Alerts (product)Socket (product)Axios (product)npm (technology)pnpm (technology)yarn (technology)