Snyk still reporting hacked Ledger package is safe, 12 hours after compromise
twitter.com
twitter.com
Socket is designed to work without the need to analyze, upload, or share your source code. The only data we collect from your repository are the manifest files (package.json, package-lock.json, yarn.lock, etc.).
We use the dependency snapshot to determine the list of packages used by your repository, perform our open source risk analysis, and produce a report.
More info here: https://docs.socket.dev/docs/faq