惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
C
Check Point Blog
腾讯CDC
Stack Overflow Blog
Stack Overflow Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
Recent Announcements
Recent Announcements
L
LangChain Blog
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
J
Java Code Geeks
博客园_首页
Jina AI
Jina AI
美团技术团队
H
Help Net Security
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
人人都是产品经理
人人都是产品经理
Y
Y Combinator Blog
S
SegmentFault 最新的问题

Socket

Fake Corepack Site Distributes Infostealer and Proxyware to ... Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr... Introducing Manifest Alerts - Socket
Introducing Repository Access Permissions and Custom Role...
Joe Werle · 2026-06-20 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

Socket now supports more granular access control for organizations with Custom Roles and Repository Access Permissions, giving teams a more precise way to manage who can do what, and where they can do it.

Modern engineering organizations rarely map cleanly to a single security team or a single set of repositories. A user might need to review alerts for one team's repositories, manage scans for another, or support a temporary project without gaining access to the entire organization.

Access control has often forced admins into a tradeoff: grant a broad built-in role, or limit collaboration. That tradeoff gets harder as organizations scale, bring in contractors, split responsibilities across teams, or add controls around sensitive repositories.

Built-in roles cover most needs, but they are not always precise enough. Repository-level boundaries matter because security data is often specific to a single repository, and admins need controls they can understand and audit.

Grant users only the access they need#

Custom Roles and Repository Access Permissions give Socket organizations a two-layer access model:

  • Custom Roles define what actions a user can perform.
  • Repository Access Permissions define which repositories those actions apply to.

Together, these controls help admins apply least-privilege access without forcing every user into a broad built-in role.

Custom Roles let admins build organization-specific roles#

Custom Roles let organizations tailor access to their internal workflows. Admins can create a role that inherits from an existing base role, or build a fully custom role from scratch for least-privilege access.

A few examples:

  • Security Analyst: views alerts, dependencies, scans, and reports.
  • AppSec Admin: manages policies and triages findings without owning billing.
  • Read-only Auditor: inspects reports and audit data without making changes.
  • Developer Contributor: views and acts on security findings for assigned repositories only.

In the dashboard, admins can:

  • Create, edit, and delete custom roles.
  • Choose a base role or start with no base role.
  • Add specific permissions and scopes.
  • See inherited permissions separately from explicitly added permissions.
  • Assign custom roles to organization members.

Repository Access Permissions scope a member to specific repositories#

Repository Access Permissions let admins limit a member's visibility and actions to the repositories they should work with. Instead of granting organization-wide access to every repository, admins can grant access to selected repositories or to all repositories, depending on the member's responsibilities.

From organization settings, admins can:

  • Manage repository access for each member.
  • View which members have configured repository access rules.
  • Grant access to selected repositories.
  • Grant or remove organization-wide repository access.
  • Audit repository access rule changes.

Socket enforces repository scope across repository lists, scans, SBOM views, and dependency inventory, along with supported API paths.

How the two features work together#

A security analyst may need to view alerts, dependency inventory, SBOM reports, and scan results. With Custom Roles, an admin defines that exact set of capabilities. With Repository Access Permissions, the admin limits those capabilities to the repositories owned by the analyst's team.

The analyst gets enough access to do the job, without broad visibility into unrelated repositories.

Example workflow

  1. An organization creates a custom role called Security Analyst.
  2. The role includes read access for alerts, dependencies, scans, and reports.
  3. An admin assigns the role to a member.
  4. The admin grants that member access to a specific set of repositories.
  5. When the member signs in, they see and interact with only the repositories they can access.

Built for least-privilege access at scale#

Custom Roles and Repository Access Permissions help large teams apply least-privilege access without blocking collaboration. They let admins:

  • Reduce unnecessary repository visibility.
  • Give contractors, auditors, and team-specific users scoped access.
  • Make onboarding and offboarding safer.
  • Align access with team ownership.
  • Improve auditability around repository access changes.
  • Avoid overusing broad Admin or Member roles.

Socket designed Repository Access Permissions for intentional configuration. Enforcement only applies once admins configure rules, so teams can adopt the model deliberately instead of having access change unexpectedly.

Existing built-in roles still work, and Custom Roles extend the current model rather than replacing it. Admins can start simple and get more granular over time. Socket logs repository access changes as audit events, and dedicated RBAC permissions govern who can manage repository access and related access-policy controls.

Get started#

Custom Roles and Repository Access Permissions are available today to all Socket organization admins in the dashboard under organization settings.

From there, admins can create organization-specific roles, assign precise permissions and scopes, and configure repository access rules by member. Members can be granted access to all repositories or only selected repositories, depending on their responsibilities.

These controls give Socket organizations a more precise way to manage access as they scale, while keeping broad defaults available where they still make sense.