gleam-lang/gleam
在 GitHub 查看Warn when a vulnerable package version is added as a dependency
Open
#5,725 创建于 2026年5月18日
help wanted
描述
Hex now contains information on CVEs that we can use to display warnings when used. Let's use this information to display a warning when a newly resolved version of a dependency is vulnerable.
We could also have a command for showing vulnerabilities for the current package versions.
Reference implementation for Elixir: https://github.com/hexpm/hex/pull/1150