-
Notifications
You must be signed in to change notification settings - Fork 122
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OpenSSF Scorecard Report Updated #1327
Conversation
The biggest change is in the Node.js repo. Seems like the scoring is affected by "62 Vulnerabilities". See full report
It is the first time that the report is showing this data for Node 🤔 |
Have we confirmed if these CVEs are valid for Node.js? If so it should have been reported via https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues somehow 😕 |
The last one in the list, GHSA-36jr-mh4h-2g58, is for d3-color which I don't think we include in Node.js or any of its dependencies. |
I tried to checkout |
OpenSSF Scorecard Report Updated. cc: @nodejs/security-wg
closes: #1326