Socket for GitHub by Socket secures every GitHub pull request by analyzing the package's behavior and security risk whenever a new dependency is added. It detects and blocks 70+ signals of supply chain risk in open source code, including known malware, possible typosquat attacks, obfuscated code, suspicious GitHub stars, unstable ownership, AI-detected potential malware, bad dependency semver, unpopular packages, wildcard dependencies, minified code, deprecated, and unmaintained packages. Socket for GitHub provides real-time dependency insights directly within the developer workflow, helping security teams focus on real threats. It offers a fast and easy 2-click install from the GitHub Marketplace, automatically analyzing projects and keeping them secure. Socket for GitHub ensures complete security of projects in every GitHub pull request and creates project health reports by uploading package.json or package-lock.json files. It can be run on CI/CD pipelines to secure the pull request workflow and allows users to look up supply chain risks for a given version of a package in the ecosystem registry.