webpack / webpack/working-groups

[SEC-WG] Audit for Webpack?

Open
#2 8 comments 1 reaction 1 assignee View on GitHub

@UlisesGascon is already working on this.

Since Jan 9, 2026.

tsc-agenda
Dominant language
No language data
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

To separate topics from webpack/working-groups#9, I’m opening this.

It might be interesting to have an audit to find vulnerabilities. For example, Express did this a long time ago (https://expressjs.com/2024/10/22/security-audit-milestone-achievement.html
). In Express’s case, it was done through https://ostif.org/
and funded by Sovereign Tech Agency. We could try to achieve the same.

Now that we have a triage team, this seems like a good idea

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.