{"version":"https://jsonfeed.org/version/1","title":"Changelog - Socket","home_page_url":"https://socket.dev/changelog","feed_url":"https://socket.dev/api/changelog/feed.json","description":"Your source for recent updates for Socket.","icon":"https://socket.dev/webmanifest/icon-512x512.png","favicon":"https://socket.dev/favicon-32x32.png","author":{"name":"Socket","url":"https://socket.dev","avatar":"https://socket.dev/webmanifest/icon-512x512.png"},"items":[{"id":"https://socket.dev/changelog/socket-now-scans-yanked-crates-io-versions-pinned-in-cargo-lock","url":"https://socket.dev/changelog/socket-now-scans-yanked-crates-io-versions-pinned-in-cargo-lock?utm_medium=feed","title":"Socket Now Scans Yanked crates.io Versions Pinned in Cargo.lock","content_html":"<p>Socket now correctly scans crates.io package versions that have been yanked but remain pinned in a project’s <code>Cargo.lock</code>, preventing failures for projects that still depend on archived crate versions.</p>","date_published":"2026-07-10T03:12:07.100Z"},{"id":"https://socket.dev/changelog/repository-scoped-api-tokens-now-support-reachability-scans","url":"https://socket.dev/changelog/repository-scoped-api-tokens-now-support-reachability-scans?utm_medium=feed","title":"Repository-Scoped API Tokens Now Support Reachability Scans","content_html":"<p>Repository-scoped API tokens can now retrieve the supported-files list required to start reachability scans. This fixes an issue where scans authenticated with a repository-scoped token could fail with a 403 error before analysis began, making it easier to use least-privilege credentials with the Socket API.</p>","date_published":"2026-07-09T03:23:00.000Z"},{"id":"https://socket.dev/changelog/packagist-package-pages-now-surface-force-pushed-tags","url":"https://socket.dev/changelog/packagist-package-pages-now-surface-force-pushed-tags?utm_medium=feed","title":"Packagist Package Pages Now Surface Force-Pushed Tags","content_html":"<p>Packagist package pages now show the full commit history for tags that have been force-pushed, with the commit currently associated with the tag highlighted. This makes it easier to identify when a published package version has been retagged and review the commits it previously referenced.</p>","date_published":"2026-07-06T04:03:00.000Z"},{"id":"https://socket.dev/changelog/fix-full-scan-metadata-now-matches-the-api-contract","url":"https://socket.dev/changelog/fix-full-scan-metadata-now-matches-the-api-contract?utm_medium=feed","title":"Fix: Full Scan Metadata Now Matches the API Contract","content_html":"<p>Full scan metadata responses now consistently include the repository, workspace, report URL, API URL, and scan type fields documented in the API contract.</p>","date_published":"2026-07-03T03:50:00.000Z"},{"id":"https://socket.dev/changelog/private-package-scores-now-display-as-n-a","url":"https://socket.dev/changelog/private-package-scores-now-display-as-n-a?utm_medium=feed","title":"Private Package Scores Now Display as N/A","content_html":"<p>Private packages that Socket cannot score now display <strong>N/A</strong> instead of a numeric score in pull request comments and dependency views. This prevents private packages from appearing to have passed or failed analysis when no score is available.</p>","date_published":"2026-07-03T03:45:00.000Z"},{"id":"https://socket.dev/changelog/fix-pull-request-pages-no-longer-break-after-renaming-a-workspace","url":"https://socket.dev/changelog/fix-pull-request-pages-no-longer-break-after-renaming-a-workspace?utm_medium=feed","title":"Fix: Pull Request Pages No Longer Break After Renaming a Workspace","content_html":"<p>Fixed an issue where pull request detail pages could return a &quot;Not Found&quot; error after a workspace was renamed, even though the pull request still appeared in the list. Existing pull request links now continue to work after workspace renames without requiring any additional action.</p>","date_published":"2026-07-02T03:28:00.000Z"},{"id":"https://socket.dev/changelog/ai-reviewed-reachability-specifications","url":"https://socket.dev/changelog/ai-reviewed-reachability-specifications?utm_medium=feed","title":"New: AI-Reviewed Reachability Specifications","content_html":"<p>Organizations can now opt in to include AI-generated reachability specifications alongside human-verified ones, giving more vulnerabilities a reachability verdict.</p><p>This setting can be enabled under <strong>Settings → Alert Scans → Reachability</strong>. Once enabled, it applies across reachability analysis and broadens coverage, with a slightly higher risk of an incorrect result.</p><p>Alert details now include a <strong>Specification</strong> field that shows whether a reachability result came from an AI-generated or human-verified specification.</p><img\n  alt=\" \"\n  loading=\"lazy\"\n  src=\"https://cdn.sanity.io/images/cgdhsj6q/production/1c6d49c65b0676270741f540ab9d13ccb24e1890-649x359.png?w=1600&q=95&fit=max&auto=format\"\n/>","date_published":"2026-06-30T02:47:00.000Z"},{"id":"https://socket.dev/changelog/redesigned-organization-switcher-for-faster-navigation","url":"https://socket.dev/changelog/redesigned-organization-switcher-for-faster-navigation?utm_medium=feed","title":"Redesigned Organization Switcher for Faster Navigation","content_html":"<p>The organization switcher has been redesigned to make it faster and easier to navigate. It now surfaces Settings and your organizations up front, and adds a searchable <strong>All organizations</strong> view for users who belong to multiple organizations.</p><p></p>","date_published":"2026-06-29T04:22:00.000Z"},{"id":"https://socket.dev/changelog/alert-titles-added-to-csv-exports","url":"https://socket.dev/changelog/alert-titles-added-to-csv-exports?utm_medium=feed","title":"Alert Titles Added to CSV Exports","content_html":"<p>Alerts CSV exports now include a human-readable <strong>Alert Title</strong> column, making it easier to identify CVEs directly from the export without cross-referencing the dashboard. <strong>Upgrade Version</strong> values are also now populated more consistently for vulnerability alerts.</p>","date_published":"2026-06-23T04:28:00.000Z"},{"id":"https://socket.dev/changelog/add-firewall-events-data-export","url":"https://socket.dev/changelog/add-firewall-events-data-export?utm_medium=feed","title":"Add Firewall events data export","content_html":"<p>For customers using Socket Firewall, it&#x27;s now possible to export event logs to an external data source. To do so, click &quot;Settings&quot; -&gt; &quot;Data Export&quot; -&gt; &quot;Create Integration&quot; and choose &quot;Telemetry events&quot; as the data type.</p>","date_published":"2026-06-16T15:27:39.629Z"}]}