Page MenuHomePhabricator

Routinely audit projects that use package.json with nodesecurity.io
Closed, DeclinedPublic

Description

(Intentionally public)

We should set up some kind of automated detection and scan for use of vulnerable packages (as direct or indirect dependencies or dev dependencies).

If you discover any such issue by using https://nodesecurity.io/tools tools yourself, please report those as private security issues.

Event Timeline

Krinkle raised the priority of this task from to Medium.
Krinkle updated the task description. (Show Details)
Krinkle subscribed.

I'd guess we could resolve this as 1) 4 years old, no action 2) nsp is basically now npm audit 3) there are several more current tasks (T203735, T179381, T174767, T96078) about security-scanning Node/TS applications.