惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
月光博客
月光博客
D
DataBreaches.Net
云风的 BLOG
云风的 BLOG
F
Fortinet All Blogs
T
The Blog of Author Tim Ferriss
Stack Overflow Blog
Stack Overflow Blog
Blog — PlanetScale
Blog — PlanetScale
aimingoo的专栏
aimingoo的专栏
U
Unit 42
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MyScale Blog
MyScale Blog
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
B
Blog
博客园_首页
G
Google Developers Blog
Recent Announcements
Recent Announcements
博客园 - 【当耐特】
P
Proofpoint News Feed
博客园 - 司徒正美
Hugging Face - Blog
Hugging Face - Blog
MongoDB | Blog
MongoDB | Blog
Last Week in AI
Last Week in AI

Socket

Fake Corepack Site Distributes Infostealer and Proxyware to ... Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr...
Socket for Linear Is Now Available - Socket
Jeppe Hasseriis · 2026-06-15 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

When Socket flags a malicious package or a vulnerable dependency, some fixes are quick: bump a version, drop a package, patch and move on. Plenty of others need to be tracked, assigned to the right person, and prioritized against everything else a team is working on. That kind of work lives in an issue tracker.

Linear has earned a loyal following among engineering teams, prized for its speed and the clarity of its workflow. So today we're excited to announce Socket for Linear, which plugs directly into your workspace. Alerts become Linear issues automatically, created with the right priority, assignee, and labels, and kept in sync as the alert changes, so the findings that belong in your tracker get there without anyone having to manually enter them.

Connect with OAuth from the Socket dashboard#

The integration connects through OAuth, and authorization happens entirely from the Socket dashboard. There is no separate app to install in a third-party admin console. An Owner or Admin in your Socket organization authorizes the workspace and selects which Linear teams Socket can create issues for. Socket only accesses the workspace and teams you authorize.

You can connect more than one Linear workspace to a single Socket organization, and a single Linear connection can be shared across multiple Socket organizations.

Create issues from any alert#

Open an alert in the Socket dashboard and click Create Ticket. Choose the Linear team, set a priority, add labels, assign the issue by email or display name, and edit the title before submitting. The new issue is linked to the alert, and a link to it appears on the alert so you can navigate straight to it.

Automate ticketing with rules#

Automated ticketing rules create and update Linear issues based on alert events across your organization. You build a rule in five steps: events, conditions, project and team, issue, and actions. Today, rules trigger on alert events. Pull request and threat feed triggers are coming soon.

Conditions let you target the alerts that matter. Filter by category, supply chain risk, vulnerability, quality, maintenance, or license, by priority, and by repository. Because Socket separates supply chain risk from vulnerabilities, you can route every critical malware alert to one team without flooding it with lower-priority findings.

Then choose the Linear team where issues are created, set the issue priority or let Socket map it automatically from the alert priority, and add labels and an assignee.

Keep issues in sync as alerts change#

Rules don't just create issues, they keep them current. Socket can update a linked issue as the alert changes, move the issue to a state you choose, such as Done, when the alert clears, and mark the alert as "ignored" when you close the ticket in Linear. The result is two-way sync between Socket alerts and Linear issues, so neither side goes stale.

Assignee support, on Linear and Jira#

We've added assignee support to both the Linear and Jira integrations: assign issues by email or display name, on both manual issues and ticketing rules.

Feature for feature, the Linear integration is on par with Socket's Jira integration, so teams on either tool get the same core workflow for routing supply chain alerts into their issue tracker.

Now in Beta#

The Linear integration is in beta and available on Business and Enterprise plans. To get started, go to Settings → Integrations → Linear in the Socket dashboard and click Connect. Full setup steps are in the Linear integration documentation.