Dependency health Supply-chain news

Supply-chain news

The incidents behind a package’s reputation. Read what happened, which releases were affected, and what the original investigators found.

Reviewed reports · last reviewed 2026-09-05. This is a selected incident record, not an exhaustive live threat feed. A past compromise does not establish that the current release is compromised.

No reviewed stories for this ecosystem yet. This does not mean no incidents have occurred.

From the security news feeds

Checked every five minutes. Last completed check: 2026-09-05T20:15:35.796Z. Package mentions are automated leads, not confirmed vulnerability findings. Their checks refresh maintenance signals and do not prove an affected version is safe.

No matching feed articles recorded yet.

High-profile vulnerabilities and your dependencies

Astra’s top-ten article ↗ collects historical CVEs from 2020–2022. It is not a live ranking or the OWASP Top 10. The mapping below explains which entries relate to package identities we check.

An identity match is a reason to investigate, not confirmation that your installed release is vulnerable. Manifest checks do not establish runtime configuration or resolve every transitive dependency.

VulnerabilityProduct / package relationship
ZeroLogon
CVE-2020-1472 ↗
Windows / Netlogon

Host and domain-controller assessment required.

Outside package-only scan coverage
Log4Shell
CVE-2021-44228 ↗
Apache Log4j Core

Applies to specific log4j-core releases, not log4j-api alone. Check resolved and bundled dependencies against Apache’s affected-version ranges.

org.apache.logging.log4j:log4j-core
ICMAD
CVE-2022-22536 ↗
SAP NetWeaver / related SAP services

Requires SAP product and deployment inventory.

Outside package-only scan coverage
ProxyLogon
CVE-2021-26855 ↗
Microsoft Exchange Server

Check the Exchange deployment; a NuGet package name cannot establish exposure.

Outside package-only scan coverage
Spring4Shell
CVE-2022-22965 ↗
Spring Framework

Historical affected branches include 5.3.0–5.3.17 and 5.2.19 and earlier. Exploitability depends on runtime and deployment; consult Spring’s advisory.

org.springframework:spring-webmvc · org.springframework:spring-webflux · org.springframework:spring-beans
Confluence RCE
CVE-2022-26134 ↗
Atlassian Confluence

Requires Confluence Server or Data Center version inventory.

Outside package-only scan coverage
vCenter RCE
CVE-2021-21972 ↗
VMware vCenter Server

Requires infrastructure product and version inventory.

Outside package-only scan coverage
Chrome use-after-free
CVE-2022-0609 ↗
Google Chrome

Check the installed browser; JavaScript package names do not identify its version.

Outside package-only scan coverage
Follina
CVE-2022-30190 ↗
Windows MSDT

Requires Windows patch and configuration assessment.

Outside package-only scan coverage
PetitPotam
CVE-2021-36942 ↗
Windows LSA / EFSRPC

Requires Windows and domain configuration assessment.

Outside package-only scan coverage

Runtime vulnerabilities on OpenCVE

Browse CVEs by vendor and product. Runtime CVEs do not automatically apply to every package in that ecosystem; verify affected versions and configurations.

News & advisory sources

RSS sources are polled independently every five minutes. Clear tracked-package mentions trigger priority checks; they do not establish that an installed version is vulnerable. Sources without an RSS link and Feedspot’s directory are browsing resources. Reviewed reports above remain curated.