Summary
Sync the CVE/GHSA advisories from WordPress core to this project.
The project already syncs tags. Would it be possible to include these advisories?
The reason for doing this would be:
- Advisories would surface when a project contains the roots/wordpress dependency, and Composer runs its
audit functionality.
- Versions marked with the vulnerability as fixed would bypass any cooldown values set in Dependabot/Renovate, allowing security releases to be integrated more quickly.
- Allow advanced projects to run fully automated upgrades while taking advantage of Composer
Additional context
No response
Summary
Sync the CVE/GHSA advisories from WordPress core to this project.
The project already syncs tags. Would it be possible to include these advisories?
The reason for doing this would be:
auditfunctionality.Additional context
No response