Security advisories
Public vulnerability reports matched against the versions the repository serves, and how you are told.
Security advisories in the main menu lists public vulnerability reports that affect plugins and themes in the catalogue, matched against the versions this repository serves, newest first. The list is filled from a vulnerability intelligence feed once it is connected; until then the page says that monitoring is not active.
What an advisory shows
- the package, its severity (Critical, High, Medium, Low or Informational) and the date it was published;
- the Affected versions and the version it is Fixed in, with a note when that fixed version is already in the repository (or not yet);
- the Remediation, usually Update to the fixed version, and a link to the full advisory at its source.
Filter the list by severity, and by whether a fixed version is available in the repository.
On the package page, an affected version carries a red label with the number of known vulnerabilities; the Security tab lists them under Known vulnerabilities.
Be told
- Watch the package with All activity or Security alerts (Stars, lists and watching).
- Under Settings → Notifications, keep Security notices on for the inbox, push or e-mail (Notifications).
You are told when an advisory affects a package you watch or, through a project, a version one of your sites runs. The advisories also come as an Atom feed (/security/advisories.atom) for your feed reader.
Questions
Is a version with an advisory withdrawn? Not automatically: many advisories concern settings or features you may not use. Update to the fixed version; if the repository withdraws a version, you are told separately.
Did this not answer your question? Contact support.