Skip to content

docs: expand Socket CLI comparison with concrete examples and structured sections#655

Open
raj-krr wants to merge 2 commits into
OWASP:mainfrom
raj-krr:docs/socket-cli-comparison-361
Open

docs: expand Socket CLI comparison with concrete examples and structured sections#655
raj-krr wants to merge 2 commits into
OWASP:mainfrom
raj-krr:docs/socket-cli-comparison-361

Conversation

@raj-krr

@raj-krr raj-krr commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Expanded the Socket CLI comparison section in website/docs/comparison.md to provide a more detailed and balanced comparison with CVE Lite CLI.

Why this change

The existing Socket CLI section was significantly shorter than the Dependabot, npm audit, OSV-Scanner, and Snyk comparisons. It did not fully explain the different security problems each tool addresses or how they complement each other.

This update adds more context around threat models, feature differences, practical use cases, and recommended workflows so developers can better understand when to use each tool.

What changed

  • Added an overview explaining the different goals of CVE Lite CLI and Socket CLI
  • Added a threat-model comparison section
  • Added a feature comparison table
  • Added practical examples for vulnerability detection and supply-chain risk detection
  • Added sections describing where each tool has advantages
  • Added a "Why results differ" section
  • Added a recommended combined workflow showing how the tools complement each other
  • Added notes about Socket's paid features and CVE Lite CLI's account-free workflow

Validation

  • Reviewed the updated documentation locally
  • Verified Markdown formatting and table structure
  • Confirmed the new section follows the same depth and structure as other comparison sections in comparison.md

User-facing impact

Does this change:

  • affect scanning behavior
  • affect output formatting
  • affect JSON output
  • affect docs only

Notes

The comparison intentionally presents Socket CLI and CVE Lite CLI as complementary tools rather than direct substitutes. The goal is to help users understand the different types of security risks each tool is designed to address.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant