gleam-lang/gleam
Vedi su GitHubWarn when a vulnerable package version is added as a dependency
Open
Aperta il 18 mag 2026
help wanted
Descrizione
Hex now contains information on CVEs that we can use to display warnings when used. Let's use this information to display a warning when a newly resolved version of a dependency is vulnerable.
We could also have a command for showing vulnerabilities for the current package versions.
Reference implementation for Elixir: https://github.com/hexpm/hex/pull/1150