roots / roots/wordpress-packager

Sync WordPress Core CVE/GHSA Advisories

Open
#1,296 6 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
PHP
Stars
43
Forks
8
Avg merge
1m
Merged PRs (30d)
7

Description

Summary

Sync the CVE/GHSA advisories from WordPress core to this project.

The project already syncs tags. Would it be possible to include these advisories?

The reason for doing this would be:

  • Advisories would surface when a project contains the roots/wordpress dependency, and Composer runs its audit functionality.
  • Versions marked with the vulnerability as fixed would bypass any cooldown values set in Dependabot/Renovate, allowing security releases to be integrated more quickly.
  • Allow advanced projects to run fully automated upgrades while taking advantage of Composer
Additional context

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the existing WordPress core tag-sync implementation and review how this project represents package metadata. Then check Composer audit advisory requirements and how fixed versions are identified. Done means CVE/GHSA advisories for roots/wordpress are available to Composer audit consumers and fixed versions are recognized for expedited upgrades.

Written by the indexing model from the issue text.

Assessment

Tech stack
php, wordpress
Domain
security, tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.