webpack / webpack/working-groups
[SEC-WG] Centralized CVE Tracking for Our Packages
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
I’ve just created a PoC to pull in all the CVEs we have across all our packages. Here’s the script (https://gist.github.com/bjohansebas/91c1056fbad6968b4bd739d53ab53d57). It can still be improved and even turned into a GitHub Action, but before moving forward, what do you think about tracking our packages’ CVEs here?
With this, we could also improve the section at https://github.com/webpack/security-wg/blob/main/docs/threat-model.md#examples-of-vulnerabilities-in-scope by referencing this new file.
Result
Security Advisories
Total: 7
webpack
Total: 7
| Repository Name | Advisories |
|---|---|
| webpack | |
| webpack-dev-middleware | |
| webpack-dev-server | |
| webpack-bundle-analyzer |
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the linked CVE-tracking PoC and the examples of vulnerabilities in scope in docs/threat-model.md. Clarify whether the project wants a maintained CVE file, a GitHub Action, or both, then define the package coverage, update process, and acceptance criteria before implementation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, github-actions
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100