socket optimize
Optimize dependencies with @socketregistry overrides
socket optimize replaces dependencies that have a Socket registry alternative with the matching @socketregistry package. It updates package.json with npm: aliases such as npm:@socketregistry/<name>@^1, then runs your package manager's install to update the lockfile.
- In a private package or a project with workspaces, the overrides go in
overridesfor npm,pnpm.overridesfor pnpm, andresolutionsfor Yarn and Bun. Other packages get bothoverridesandresolutions. vlt is not supported. - The project needs a
package.jsonand a lockfile. - By default each override uses a caret range on the major version.
--pinuses the exact latest version. --prodis not supported for Yarn Berry or Bun.
socket optimize --help
$ socket optimize --help
Optimize dependencies with @socketregistry overrides
Usage
$ socket optimize [options] [CWD=.]
API Token Requirements
- Quota: 100 units
- Permissions: packages:list
Options
--pin Pin overrides to latest version
--prod Add overrides for production dependencies only
Examples
$ socket optimize
$ socket optimize ./path/to/project --pinUpdated 17 days ago
Did this page help you?