Socket launched Manifest Alerts to flag supply chain risks in project configuration rather than specific packages. The initial alert detects missing lockfiles that make dependency resolution non-reproducible, addressing visibility gaps exposed during incidents like the Axios compromise.