gleam-lang/gleam

Warn when a vulnerable package version is added as a dependency

Open

#5,725 创建于 2026年5月18日

在 GitHub 查看
 (2 评论) (0 反应) (0 负责人)Rust (21,417 star) (960 fork)batch import
help wanted

描述

Hex now contains information on CVEs that we can use to display warnings when used. Let's use this information to display a warning when a newly resolved version of a dependency is vulnerable.

We could also have a command for showing vulnerabilities for the current package versions.

Reference implementation for Elixir: https://github.com/hexpm/hex/pull/1150

贡献者指南