gleam-lang/gleam
Ver no GitHubWarn when a vulnerable package version is added as a dependency
Open
#5.725 aberto em 18 de mai. de 2026
help wanted
Description
Hex now contains information on CVEs that we can use to display warnings when used. Let's use this information to display a warning when a newly resolved version of a dependency is vulnerable.
We could also have a command for showing vulnerabilities for the current package versions.
Reference implementation for Elixir: https://github.com/hexpm/hex/pull/1150