webpack / webpack/working-groups
[SEC-WG] Audit for Webpack?
Open
@UlisesGascon is already working on this.
Since Jan 9, 2026.
tsc-agenda
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
To separate topics from webpack/working-groups#9, I’m opening this.
It might be interesting to have an audit to find vulnerabilities. For example, Express did this a long time ago (https://expressjs.com/2024/10/22/security-audit-milestone-achievement.html
). In Express’s case, it was done through https://ostif.org/
and funded by Sovereign Tech Agency. We could try to achieve the same.
Now that we have a triage team, this seems like a good idea
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.