Skip to main content
MeteorGPLby WebbingApps

Security advisories

Public vulnerability reports matched against the versions the repository serves, and how you are told.

Security advisories in the main menu lists public vulnerability reports that affect plugins and themes in the catalogue, matched against the versions this repository serves, newest first. The list is filled from a vulnerability intelligence feed once it is connected; until then the page says that monitoring is not active.

What an advisory shows

  • the package, its severity (Critical, High, Medium, Low or Informational) and the date it was published;
  • the Affected versions and the version it is Fixed in, with a note when that fixed version is already in the repository (or not yet);
  • the Remediation, usually Update to the fixed version, and a link to the full advisory at its source.

Filter the list by severity, and by whether a fixed version is available in the repository.

On the package page, an affected version carries a red label with the number of known vulnerabilities; the Security tab lists them under Known vulnerabilities.

Be told

  1. Watch the package with All activity or Security alerts (Stars, lists and watching).
  2. Under Settings → Notifications, keep Security notices on for the inbox, push or e-mail (Notifications).

You are told when an advisory affects a package you watch or, through a project, a version one of your sites runs. The advisories also come as an Atom feed (/security/advisories.atom) for your feed reader.

Questions

Is a version with an advisory withdrawn? Not automatically: many advisories concern settings or features you may not use. Update to the fixed version; if the repository withdraws a version, you are told separately.

Did this not answer your question? Contact support.

Send feedback

What works, what does not, what is missing: a few words help.

Only if you would like a reply.

Taken in your browser, without this window. Passwords, what you typed into forms, keys and tokens are left out as grey blocks; you can hide more before sending. We keep screenshots for 90 days.

We store it with the page address, your language, window size, browser and IP address, and your e-mail address if you give one. The IP address and browser are deleted after 90 days. Privacy policy.

All languages