Skip to content

Sync WordPress Core CVE/GHSA Advisories #63

Description

@michaelbragg

Sync the CVE/GHSA advisories from WordPress core to this project.

The project already syncs tags. Would it be possible to include these advisories?

The reason for doing this would be:

  • Advisories would surface when a project contains the johnpbloch/wordpress dependency, and Composer runs its audit functionality.
  • Versions marked with the vulnerability as fixed would bypass any cooldown values set in Dependabot/Renovate, allowing security releases to be integrated more quickly.
  • Allow advanced projects to run fully automated upgrades while taking advantage of Composer

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions