Skip to content

[SEC-WG] Centralized CVE Tracking for Our Packages #28

@bjohansebas

Description

@bjohansebas

I’ve just created a PoC to pull in all the CVEs we have across all our packages. Here’s the script (https://gist.github.com/bjohansebas/91c1056fbad6968b4bd739d53ab53d57). It can still be improved and even turned into a GitHub Action, but before moving forward, what do you think about tracking our packages’ CVEs here?

With this, we could also improve the section at https://github.com/webpack/security-wg/blob/main/docs/threat-model.md#examples-of-vulnerabilities-in-scope by referencing this new file.

Result

Security Advisories

Total: 7

webpack

Total: 7

Repository Name Advisories
webpack
webpack-dev-middleware
webpack-dev-server
webpack-bundle-analyzer

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions