更新: 270 个文件 - 2026-03-28 03:48:48

这个提交包含在:
hao
2026-03-28 03:48:48 -07:00
父节点 bce7f9ef61
当前提交 d560e6b421
修改 270 个文件,包含 13395 行新增2077 行删除

查看文件

@@ -7,13 +7,14 @@
"title": "PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables",
"summary": "### Impact\nMultiple stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO: an attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates.\n\n### Patches\nPatched on 8.2.5 and 9.1.0\n\n### Workarounds\nNone\n\n### References\nNone",
"published_at": "2026-03-25T19:41:50Z",
"updated_at": "2026-03-25T19:48:31.156136Z",
"updated_at": "2026-03-27T21:52:37.272493Z",
"severity": "low",
"cvss_score": 3.1,
"exploit_status": "unknown",
"source_confidence": "ecosystem-authority",
"official_source_url": "https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-35pf-37c6-jxjv",
"secondary_source_urls": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-33673",
"https://github.com/PrestaShop/PrestaShop",
"https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5",
"https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0"
@@ -145,6 +146,7 @@
"patched_version": "9.1.0",
"version_evidence_sources": [
"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-35pf-37c6-jxjv",
"https://nvd.nist.gov/vuln/detail/CVE-2026-33673",
"https://github.com/PrestaShop/PrestaShop",
"https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5",
"https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0"

查看文件

@@ -7,13 +7,14 @@
"title": "PrestaShop: Improper Use of Validation Framework",
"summary": "### Impact\nFix improper use of validation framework\n\n### Patches\nPatched in 8.2.5 and 9.1.0\n\n### Workarounds\nNone\n\n### References\nnone",
"published_at": "2026-03-25T19:40:42Z",
"updated_at": "2026-03-25T19:49:27.843572Z",
"updated_at": "2026-03-27T21:52:10.658795Z",
"severity": "low",
"cvss_score": 3.1,
"exploit_status": "unknown",
"source_confidence": "ecosystem-authority",
"official_source_url": "https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-283w-xf3q-788v",
"secondary_source_urls": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-33674",
"https://github.com/PrestaShop/PrestaShop",
"https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5",
"https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0"
@@ -144,6 +145,7 @@
"patched_version": "8.2.5",
"version_evidence_sources": [
"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-283w-xf3q-788v",
"https://nvd.nist.gov/vuln/detail/CVE-2026-33674",
"https://github.com/PrestaShop/PrestaShop",
"https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5",
"https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0"

文件差异因一行或多行过长而隐藏

查看文件

@@ -0,0 +1,200 @@
{
"canonical_id": "traefik--CVE-2026-33433",
"system_id": "traefik",
"display_name": "Traefik",
"category": "servers",
"advisory_mode": "server",
"title": "Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField",
"summary": "## Summary\n\nThere is a potential vulnerability in Traefik's Basic and Digest authentication middlewares when `headerField` is configured with a non-canonical HTTP header name.\n\nAn authenticated attacker with valid credentials can inject the canonical version of the configured header to impersonate any identity to the backend. Because Traefik writes the authenticated username using a non-canonical map key, it creates a separate header entry rather than overwriting the attacker's canonical one \u2014 causing most backend frameworks to read the attacker-controlled value instead.\n\n## Patches\n\n- <https://github.com/traefik/traefik/releases/tag/v2.11.42>\n- <https://github.com/traefik/traefik/releases/tag/v3.6.12>\n- <https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3>\n\n## For more information\n\nIf there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).\n\n---\n\n<details>\n<summary>Original Description</summary>\n\n### Summary\n\nWhen `headerField` is configured with a non-canonical HTTP header name (e.g., `x-auth-user` instead of `X-Auth-User`), an authenticated attacker can inject a canonical version of that header to impersonate any identity to the backend. The backend receives two header entries \u2014 the attacker-injected canonical one is read first, overriding Traefik's non-canonical write.\n\nTested on Traefik v3.6.10.\n\n### Details\n\nAt `pkg/middlewares/auth/basic_auth.go:92`, the authenticated username is written using direct map assignment:\n\n```go\nreq.Header[b.headerField] = []string{user}\n```\n\nGo's `http.Header` map is keyed by canonical names (e.g., `X-Auth-User`). Direct assignment with a non-canonical key (`x-auth-user`) creates a separate map entry from any canonical-key entry already present. The attacker's `X-Auth-User: superadmin` occupies the canonical slot and is never overwritten by Traefik's non-canonical write.\n\nThe same bug exists in `pkg/middlewares/auth/digest_auth.go:100`. Notably, `forward.go:254` correctly uses `http.CanonicalHeaderKey()`, showing the fix pattern already exists in the codebase.\n\n### PoC\n\n**Traefik config (YAML, Docker labels, or REST API):**\n\n```yaml\nmiddlewares:\n auth:\n basicAuth:\n users: [\"admin:$2y$05$...\"]\n headerField: \"x-auth-user\"\n```\n\n**Normal request (baseline):**\n\n```bash\ncurl -u admin:admin http://traefik/secure/test\n# Backend receives: x-auth-user: admin\n# Identity = admin \u2713\n```\n\n**Attack request:**\n\n```bash\ncurl -u admin:admin -H \"X-Auth-User: superadmin\" http://traefik/secure/test\n# Backend receives BOTH headers:\n# X-Auth-User: superadmin \u2190 attacker-injected (canonical key, read first by most frameworks)\n# x-auth-user: admin \u2190 Traefik-set (non-canonical, ignored by most frameworks)\n# Identity seen by backend = superadmin \u2717\n```\n\n**Control test** \u2014 when `headerField` uses canonical casing (`X-Auth-User`), the attack fails. Traefik's write correctly overwrites the attacker's header.\n\nThis is realistic because YAML conventions favor lowercase keys, Traefik docs don't warn about canonicalization, and the pattern of backends trusting the `headerField` header is recommended in Traefik's own documentation.\n\n**Fix suggestion:**\n\n```go\n// basic_auth.go:92 and digest_auth.go:100 \u2014 change:\nreq.Header[b.headerField] = []string{user}\n// to:\nreq.Header.Set(b.headerField, user)\n```\n\nAlso strip any incoming `headerField` header before the auth check with `req.Header.Del(b.headerField)`.\n\n### Impact\n\nAn authenticated attacker with valid credentials (even low-privilege) can impersonate any other user identity to backend services. If backends use the `headerField` header for authorization decisions (which is the intended use case per Traefik docs), this enables privilege escalation \u2014 e.g., a regular user impersonating an admin.\n\nThe attack requires the operator to configure `headerField` with a non-canonical header name, which is the natural thing to do in YAML and is not warned against in documentation.\n\n</details>",
"published_at": "2026-03-27T20:35:53Z",
"updated_at": "2026-03-27T20:49:46.252668Z",
"severity": "medium",
"cvss_score": 4.0,
"exploit_status": "unknown",
"source_confidence": "official",
"official_source_url": "https://github.com/traefik/traefik/security/advisories/GHSA-qr99-7898-vr7c",
"secondary_source_urls": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-33433",
"https://github.com/traefik/traefik",
"https://github.com/traefik/traefik/releases/tag/v2.11.42",
"https://github.com/traefik/traefik/releases/tag/v3.6.11",
"https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3"
],
"aliases": [
"CVE-2026-33433",
"GHSA-qr99-7898-vr7c"
],
"cve_ids": [
"CVE-2026-33433"
],
"ghsa_ids": [
"GHSA-qr99-7898-vr7c"
],
"osv_ids": [
"GHSA-qr99-7898-vr7c"
],
"affected_versions": [
"introduced=0, fixed<2.11.42",
"introduced=3.0.0-beta1, fixed<3.6.12",
"introduced=3.7.0-ea.1, fixed<3.7.0-ea.3"
],
"fixed_versions": [
"2.11.42",
"3.6.12",
"3.7.0-ea.3"
],
"package_name": "github.com/traefik/traefik/v3",
"render_markdown": false,
"case_path": null,
"secure_code_topics": [
"proxy-trust-boundary",
"request-smuggling-boundary",
"dependency-upgrade-policy"
],
"status": "generated",
"triage_reasons": [],
"entity_refs": [
{
"entity_id": "traefik",
"entity_type": "system",
"relation": "root-system",
"root_system_id": "traefik",
"official": true
},
{
"entity_id": "traefik--repo--github-com-traefik-traefik-v3",
"entity_type": "repo",
"relation": "affected-component",
"root_system_id": "traefik",
"official": false
}
],
"affected_components": [
{
"name": "traefik / traefik / v3",
"entity_id": "traefik--repo--github-com-traefik-traefik-v3",
"scope": "repo",
"package_name": "github.com/traefik/traefik/v3",
"official": false
}
],
"affected_version_ranges": [
"introduced=0, fixed<2.11.42",
"introduced=3.0.0-beta1, fixed<3.6.12",
"introduced=3.7.0-ea.1, fixed<3.7.0-ea.3"
],
"fixed_version_ranges": [
"2.11.42",
"3.6.12",
"3.7.0-ea.3"
],
"introduced_version": "introduced=3.7.0-ea.1, fixed<3.7.0-ea.3",
"patched_version": "2.11.42",
"version_evidence_sources": [
"https://github.com/traefik/traefik/security/advisories/GHSA-qr99-7898-vr7c",
"https://nvd.nist.gov/vuln/detail/CVE-2026-33433",
"https://github.com/traefik/traefik",
"https://github.com/traefik/traefik/releases/tag/v2.11.42",
"https://github.com/traefik/traefik/releases/tag/v3.6.11",
"https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3"
],
"affected_version_refs": [
"traefik--repo--github-com-traefik-traefik-v3--introduced-0-fixed-2-11-42",
"traefik--repo--github-com-traefik-traefik-v3--introduced-3-0-0-beta1-fixed-3-6-12",
"traefik--repo--github-com-traefik-traefik-v3--introduced-3-7-0-ea-1-fixed-3-7-0-ea-3"
],
"fixed_version_refs": [
"traefik--repo--github-com-traefik-traefik-v3--2-11-42",
"traefik--repo--github-com-traefik-traefik-v3--3-6-12",
"traefik--repo--github-com-traefik-traefik-v3--3-7-0-ea-3"
],
"patched_version_refs": [
"traefik--repo--github-com-traefik-traefik-v3--2-11-42"
],
"version_sync_confidence": "high",
"advisory_scope": "repo",
"version_confidence": "high",
"version_gap_reason": "",
"version_resolution_needed": false,
"workflow": {
"workflow_id": "traefik--CVE-2026-33433--workflow",
"vuln_family": "proxy-boundary",
"entry_surface": "proxy-header-or-trust-boundary",
"preconditions": [
"\u4ec5\u5728 lab-local\u3001lab-public \u6216\u660e\u786e\u6388\u6743\u76ee\u6807\u4e2d\u6267\u884c\u3002",
"\u786e\u8ba4\u76ee\u6807\u547d\u4e2d\u7248\u672c\u65ad\u8a00: introduced=0, fixed<2.11.42, introduced=3.0.0-beta1, fixed<3.6.12, introduced=3.7.0-ea.1, fixed<3.7.0-ea.3",
"\u82e5\u5bf9\u8c61\u5c5e\u4e8e `repo`\uff0c\u5148\u786e\u8ba4\u6269\u5c55/\u4ed3\u5e93/\u5305\u5df2\u542f\u7528\u5e76\u5904\u4e8e\u53d7\u5f71\u54cd\u7248\u672c\u3002"
],
"required_role": "reverse-proxy-or-edge-client",
"affected_version_assertion": [
"introduced=0, fixed<2.11.42",
"introduced=3.0.0-beta1, fixed<3.6.12",
"introduced=3.7.0-ea.1, fixed<3.7.0-ea.3"
],
"trigger_vector": "\u5bf9 `proxy-boundary` \u5bb6\u65cf\u5165\u53e3\u6295\u9012\u6700\u5c0f\u5316\u3001\u53ef\u5ba1\u8ba1\u3001\u53ef\u56de\u6eda\u7684\u53d7\u63a7\u8f93\u5165\uff0c\u6bd4\u8f83\u4fee\u590d\u524d\u540e\u5dee\u5f02\u3002",
"request_or_ui_path": [
"/middleware",
"/x-forwarded-* trust path"
],
"input_shape": "\u63d0\u4ea4\u53d7\u63a7\u4ee3\u7406\u5934\u6216\u6765\u6e90\u5934\uff0c\u9a8c\u8bc1\u4fe1\u4efb\u8fb9\u754c\u548c\u56de\u6e90\u9274\u6743\u3002",
"expected_unsafe_behavior": "\u4ec5\u51ed\u4ee3\u7406\u5934\u5373\u53ef\u8d8a\u8fc7\u9274\u6743\u6216\u6765\u6e90\u63a7\u5236\u3002",
"server_evidence_points": [
"\u5e94\u7528\u65e5\u5fd7\u4e2d\u7684\u547d\u4e2d\u8def\u5f84\u3001\u9274\u6743\u51b3\u7b56\u548c\u5f02\u5e38\u6808",
"\u53cd\u5411\u4ee3\u7406\u6216\u8fb9\u754c\u5c42\u65e5\u5fd7\u4e2d\u7684\u8bf7\u6c42\u5934\u3001\u6765\u6e90 IP \u4e0e\u8def\u7531\u51b3\u7b56"
],
"browser_evidence_points": [
"\u57fa\u7ebf\u622a\u56fe\u4e0e\u653b\u51fb\u540e\u622a\u56fe\u7684 DOM/\u89c6\u89c9\u5dee\u5f02",
"console\u3001network \u4e0e response metadata \u4e2d\u7684\u5f02\u5e38\u4fe1\u53f7"
],
"db_or_fs_evidence_points": [
"\u6570\u636e\u5e93\u4e2d\u65b0\u589e/\u8d8a\u6743\u8bfb\u53d6\u7684\u6d4b\u8bd5\u6570\u636e",
"\u6587\u4ef6\u7cfb\u7edf\u4e2d\u65b0\u589e\u4e0a\u4f20\u6837\u672c\u3001\u7f13\u5b58\u6761\u76ee\u6216\u8d8a\u6743\u8bfb\u53d6\u75d5\u8ff9"
],
"detection_signals": [
"WAF / reverse proxy \u5f02\u5e38\u65e5\u5fd7\u3001\u8bbf\u95ee\u65e5\u5fd7\u548c\u544a\u8b66",
"\u5e94\u7528\u5ba1\u8ba1\u65e5\u5fd7\u4e2d\u7684\u6743\u9650\u9519\u8bef\u3001\u91cd\u5b9a\u5411\u5f02\u5e38\u3001\u6a21\u677f\u6e32\u67d3\u6216\u4e0a\u4f20\u843d\u76d8\u4e8b\u4ef6",
"\u4e0a\u6e38\u4ee3\u7406\u4e0e\u5e94\u7528\u5c42\u5bf9 Content-Length / Transfer-Encoding / forwarded headers \u7684\u89e3\u91ca\u5dee\u5f02"
],
"mitigation_summary": "\u4f18\u5148\u5347\u7ea7\u5230\u4fee\u590d\u7248\u672c\uff0c\u5e76\u540c\u65f6\u6536\u7d27\u8f93\u5165\u6821\u9a8c\u3001\u670d\u52a1\u7aef\u9274\u6743\u3001\u4ee3\u7406\u4fe1\u4efb\u8fb9\u754c\u3001\u6269\u5c55\u5b89\u88c5\u4fe1\u4efb\u548c\u5ba1\u8ba1\u65e5\u5fd7\u3002",
"patch_validation_steps": [
"\u786e\u8ba4\u76ee\u6807\u7248\u672c\u4ece `introduced=0, fixed<2.11.42, introduced=3.0.0-beta1, fixed<3.6.12, introduced=3.7.0-ea.1, fixed<3.7.0-ea.3` \u5347\u7ea7\u6216\u56de\u79fb\u5230 `2.11.42`\u3002",
"\u4fdd\u7559\u540c\u4e00\u7ec4\u53d7\u63a7\u8f93\u5165\uff0c\u5728\u4fee\u590d\u524d\u540e\u5206\u522b\u6267\u884c\u5e76\u6bd4\u5bf9\u54cd\u5e94\u3001\u65e5\u5fd7\u4e0e\u6d4f\u89c8\u5668\u8bc1\u636e\u3002",
"\u786e\u8ba4\u4fee\u590d\u540e\u4ec5\u4fdd\u7559\u9884\u671f\u4e1a\u52a1\u884c\u4e3a\uff0c\u4e0d\u518d\u89e6\u53d1\u8d8a\u6743\u3001\u56de\u663e\u3001\u5f02\u5e38\u6e32\u67d3\u6216\u9519\u8bef\u8bf7\u6c42\u3002",
"\u8865\u5145 `proxy-boundary` \u65cf\u81ea\u52a8\u5316\u56de\u5f52\uff0c\u907f\u514d\u540c\u7c7b\u8def\u5f84\u5728\u63d2\u4ef6\u3001\u4e3b\u9898\u6216\u4ee3\u7406\u94fe\u4e2d\u56de\u5f52\u3002"
],
"lab_safety_notes": [
"\u53ea\u4f7f\u7528\u56de\u73af\u5730\u5740\u3001\u54e8\u5175\u76ee\u6807\u3001\u65e0\u5bb3\u6837\u672c\u6216\u53ef\u56de\u6eda\u6d4b\u8bd5\u6570\u636e\u3002",
"\u7981\u6b62\u9020\u6210\u6301\u4e45\u7834\u574f\u3001\u8d8a\u6743\u4e0b\u8f7d\u771f\u5b9e\u6570\u636e\u6216\u4e0d\u53ef\u56de\u6eda side effect\u3002",
"\u5982\u9700\u6d4f\u89c8\u5668\u8bc1\u636e\uff0c\u4fdd\u7559 baseline / proof \u4e24\u4efd\u5feb\u7167\u4ee5\u53ca console / network \u8bb0\u5f55\u3002"
],
"review_state": "ready"
},
"verification_status": "triage-manual",
"verification_mode": "synthetic",
"last_verified_at": null,
"last_run_id": null,
"evidence_bundle": null,
"historical_status": null,
"latest_status": null,
"browser_evidence": {
"required": false,
"present": false,
"refs": []
},
"repro_profile_id": "proxy-boundary-generic",
"artifact_mode": "synthetic",
"blocked_reason": null,
"metadata": {
"source_names": [
"OSV Traefik"
],
"source_kinds": [
"osv-batch"
],
"candidate_count": 1,
"entity_ref_count": 2,
"advisory_scope": "repo",
"version_confidence": "high",
"workflow_id": "traefik--CVE-2026-33433--workflow"
}
}

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 18,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/angular/angular/security/advisories/GHSA-prjf-86w9-mfqv",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 18,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 1,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Apache HTTPD Security"
],

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Apache Tomcat Security"
],

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/withastro/astro/security/advisories/GHSA-wrwg-2hg8-v723",

查看文件

@@ -32,7 +32,7 @@
],
"version_sync_status": "green",
"security_version_count": 28,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/withastro/astro/security/advisories/GHSA-c4pw-33h3-35xw",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 32,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"https://github.com/caddyserver/caddy/security/advisories/GHSA-5r3v-vc8m-m96g",

查看文件

@@ -24,7 +24,7 @@
],
"version_sync_status": "green",
"security_version_count": 5,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"https://github.com/caddyserver/caddy/security/advisories/GHSA-4xrr-hq4w-6vf4",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 7,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 1,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"Directus GitHub Advisories"

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 1,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Directus GitHub Advisories"
],

查看文件

@@ -34,7 +34,7 @@
],
"version_sync_status": "green",
"security_version_count": 80,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Discourse Release Notes RSS",
"Discourse Security RSS"

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 160,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://nvd.nist.gov/vuln/detail/CVE-2019-11358"

查看文件

@@ -38,7 +38,7 @@
],
"version_sync_status": "green",
"security_version_count": 160,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Django Security Weblog",
"Django Security Releases Archive"

查看文件

@@ -27,7 +27,7 @@
],
"version_sync_status": "green",
"security_version_count": 74,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Drupal Security Advisories RSS"
],

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"https://github.com/labstack/echo/pull/1718",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/evanw/esbuild/security/advisories/GHSA-67mh-4wv8-2f99"

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/fastify/fastify/security/advisories/GHSA-573f-x89g-hqp9",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 22,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726"

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 22,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -12,18 +12,19 @@
"repo_url": "https://github.com/TryGhost/Ghost",
"package_registry": "",
"marketplace_url": "",
"latest_version": "6.23.0",
"latest_version": "6.24.0",
"version_scheme": "semver-ish",
"latest_release_at": "2026-03-26T15:04:27Z",
"latest_release_url": "https://github.com/TryGhost/Ghost/releases/tag/v6.23.0",
"latest_release_at": "2026-03-27T15:27:44Z",
"latest_release_url": "https://github.com/TryGhost/Ghost/releases/tag/v6.24.0",
"version_source_refs": [
"https://github.com/TryGhost/Ghost/releases/tag/v6.22.1",
"https://github.com/login?return_to=%2FTryGhost%2FGhost",
"https://github.com/TryGhost/Ghost/releases/tag/v6.23.0"
"https://github.com/TryGhost/Ghost/releases/tag/v6.23.0",
"https://github.com/TryGhost/Ghost/releases/tag/v6.24.0"
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"Ghost GitHub Advisories"

查看文件

@@ -12,16 +12,16 @@
"repo_url": "",
"package_registry": "",
"marketplace_url": "",
"latest_version": "6.23.0",
"latest_version": "6.24.0",
"version_scheme": "vendor",
"latest_release_at": "2026-03-26T15:04:27Z",
"latest_release_url": "https://github.com/TryGhost/Ghost/releases/tag/v6.23.0",
"latest_release_at": "2026-03-27T15:27:44Z",
"latest_release_url": "https://github.com/TryGhost/Ghost/releases/tag/v6.24.0",
"version_source_refs": [
"https://github.com/login?return_to=%2FTryGhost%2FGhost"
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Ghost GitHub Advisories"
],

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"https://nvd.nist.gov/vuln/detail/CVE-2020-28483",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 627,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"GitLab Security Releases Atom"
],

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://www.npmjs.com/advisories/1482"

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"HAProxy Blog Feed"
],

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -25,7 +25,7 @@
],
"version_sync_status": "green",
"security_version_count": 5,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Joomla Security Centre"
],

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -12,7 +12,7 @@
"repo_url": "",
"package_registry": "https://www.npmjs.com/package/koa",
"marketplace_url": "",
"latest_version": "3.1.2",
"latest_version": "3.2.0",
"version_scheme": "semver-ish",
"latest_release_at": "",
"latest_release_url": "https://www.npmjs.com/package/koa",
@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/koajs/koa/security/advisories/GHSA-7gcc-r8m5-44qm"

查看文件

@@ -12,14 +12,14 @@
"repo_url": "",
"package_registry": "",
"marketplace_url": "",
"latest_version": "3.1.2",
"latest_version": "3.2.0",
"version_scheme": "vendor",
"latest_release_at": "",
"latest_release_url": "https://www.npmjs.com/package/koa",
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 103,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Packagist p2",
"https://github.com/laravel/framework/security/advisories/GHSA-66hf-2p6w-jqfw"

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 103,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -25,7 +25,7 @@
],
"version_sync_status": "green",
"security_version_count": 3,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"Sansec Research"

查看文件

@@ -24,7 +24,7 @@
],
"version_sync_status": "green",
"security_version_count": 3,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Sansec Research"
],

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 759,
"last_version_synced_at": "2026-03-27T09:30:49+00:00",
"last_version_synced_at": "2026-03-28T09:18:13+00:00",
"latest_version_evidence": [
"Mattermost Security Updates JSON",
"https://securityupdates.mattermost.com/security_updates.json",

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 756,
"last_version_synced_at": "2026-03-27T09:30:49+00:00",
"last_version_synced_at": "2026-03-28T09:18:14+00:00",
"latest_version_evidence": [
"Mattermost Security Updates JSON",
"https://securityupdates.mattermost.com/security_updates.json",

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 764,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"Mattermost Security Updates JSON",
"advisory-fixed-version",

查看文件

@@ -36,7 +36,7 @@
],
"version_sync_status": "green",
"security_version_count": 818,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"https://nvd.nist.gov/vuln/detail/CVE-2026-22545",

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 3097,
"last_version_synced_at": "2026-03-27T09:30:48+00:00",
"last_version_synced_at": "2026-03-28T09:18:12+00:00",
"latest_version_evidence": [
"Mattermost Security Updates JSON"
],

查看文件

@@ -28,7 +28,7 @@
],
"version_sync_status": "green",
"security_version_count": 254,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"MediaWiki Announce RSS"
],

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -35,7 +35,7 @@
],
"version_sync_status": "green",
"security_version_count": 168,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/vercel/next.js",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 168,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -26,7 +26,7 @@
],
"version_sync_status": "green",
"security_version_count": 11,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/nuxt/nuxt/security/advisories/GHSA-vf6r-87q4-2vjf",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 11,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"OpenCart Releases"

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 2,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"OpenCart Releases"
],

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"GitHub Releases API"
],

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"phpMyAdmin Security Page"
],

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 41,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"Packagist p2",
"https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-35pf-37c6-jxjv",
@@ -41,7 +41,7 @@
"workflow_complete_advisory_count": 2,
"version_mapped_advisory_count": 2,
"first_advisory_at": "2026-03-25T19:40:42+00:00",
"latest_advisory_at": "2026-03-25T19:49:27+00:00",
"latest_advisory_at": "2026-03-27T21:52:37+00:00",
"advisory_ids": [
"prestashop--CVE-2026-33673",
"prestashop--CVE-2026-33674"

查看文件

@@ -28,7 +28,7 @@
],
"version_sync_status": "green",
"security_version_count": 9,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"Friends Of Presta Security",

查看文件

@@ -26,7 +26,7 @@
],
"version_sync_status": "green",
"security_version_count": 50,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"GitHub PrestaShop Advisories",
"Friends Of Presta Security",
@@ -44,7 +44,7 @@
"workflow_complete_advisory_count": 114,
"version_mapped_advisory_count": 2,
"first_advisory_at": "2008-12-31T11:30:00+00:00",
"latest_advisory_at": "2026-03-25T19:49:27+00:00",
"latest_advisory_at": "2026-03-27T21:52:37+00:00",
"advisory_ids": [
"prestashop--07b452707c",
"prestashop--080f1ad67c",

查看文件

@@ -26,7 +26,7 @@
],
"version_sync_status": "green",
"security_version_count": 102,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"npm latest",
"https://nvd.nist.gov/vuln/detail/CVE-2007-5379",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 102,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 12,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"npm latest",
"https://nvd.nist.gov/vuln/detail/CVE-2018-6341"

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 6,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/facebook/react",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 18,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"Redmine Security Advisories"
],

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"GitHub Saleor Advisories"

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"GitHub Saleor Advisories"
],

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"Shopware Security Advisories"

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [
"Shopware Security Advisories"
],

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 22,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"advisory-fixed-version",
"https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-cm59-pr5q-cw85"

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 22,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:15+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "source-gap",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 92,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"advisory-fixed-version",
"https://nvd.nist.gov/vuln/detail/CVE-2026-22732"

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 92,
"last_version_synced_at": "2026-03-27T09:30:50+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"Strapi GitHub Advisories"

查看文件

@@ -21,7 +21,7 @@
],
"version_sync_status": "green",
"security_version_count": 0,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"Strapi GitHub Advisories"
],

查看文件

@@ -23,7 +23,7 @@
],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/sveltejs/kit/security/advisories/GHSA-88qp-p4qg-rqm6",

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 220,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"Packagist p2",
"https://github.com/symfony/symfony/security/advisories/GHSA-5pv8-ppvj-4h68"

查看文件

@@ -19,7 +19,7 @@
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 220,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",

查看文件

@@ -24,7 +24,7 @@
],
"version_sync_status": "green",
"security_version_count": 8,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"https://github.com/traefik/traefik/security/advisories/GHSA-wvvq-wgcr-9q48",

查看文件

@@ -33,11 +33,13 @@
"https://github.com/traefik/traefik/security/advisories/GHSA-g3hg-j4jv-cwfr",
"https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w",
"https://github.com/traefik/traefik/releases/tag/v2.11.42",
"https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3"
"https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3",
"https://github.com/traefik/traefik/security/advisories/GHSA-qr99-7898-vr7c",
"https://github.com/traefik/traefik/security/advisories/GHSA-67jx-r9pv-98rj"
],
"version_sync_status": "green",
"security_version_count": 55,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"security_version_count": 62,
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"GitHub Releases API",
"https://github.com/traefik/traefik/security/advisories/GHSA-gxrv-wf35-62w9",
@@ -54,7 +56,9 @@
"https://github.com/traefik/traefik/security/advisories/GHSA-4hjq-9h5c-252j",
"https://github.com/traefik/traefik/security/advisories/GHSA-g3hg-j4jv-cwfr",
"https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w",
"advisory-fixed-version"
"advisory-fixed-version",
"https://github.com/traefik/traefik/security/advisories/GHSA-qr99-7898-vr7c",
"https://github.com/traefik/traefik/security/advisories/GHSA-67jx-r9pv-98rj"
],
"catalog_source": "",
"catalog_reason": "",
@@ -64,11 +68,11 @@
"history_backfill_status": "complete",
"latest_sync_status": "green",
"official_source_covered": true,
"advisory_count": 17,
"workflow_complete_advisory_count": 17,
"version_mapped_advisory_count": 17,
"advisory_count": 19,
"workflow_complete_advisory_count": 19,
"version_mapped_advisory_count": 19,
"first_advisory_at": "2024-07-09T19:34:07+00:00",
"latest_advisory_at": "2026-03-23T18:56:05+00:00",
"latest_advisory_at": "2026-03-27T20:49:46+00:00",
"advisory_ids": [
"traefik--CVE-2024-39321",
"traefik--CVE-2024-45410",
@@ -83,6 +87,8 @@
"traefik--CVE-2026-29054",
"traefik--CVE-2026-29777",
"traefik--CVE-2026-32595",
"traefik--CVE-2026-32695",
"traefik--CVE-2026-33433",
"traefik--GHSA-4hjq-9h5c-252j",
"traefik--GHSA-5423-jcjm-2gpv",
"traefik--GHSA-gv8r-9rw9-9697",

查看文件

@@ -18,8 +18,8 @@
"latest_release_url": "https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3",
"version_source_refs": [],
"version_sync_status": "green",
"security_version_count": 63,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"security_version_count": 70,
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [],
"catalog_source": "",
"catalog_reason": "",
@@ -29,11 +29,11 @@
"history_backfill_status": "seeded",
"latest_sync_status": "green",
"official_source_covered": true,
"advisory_count": 45,
"workflow_complete_advisory_count": 45,
"version_mapped_advisory_count": 18,
"advisory_count": 47,
"workflow_complete_advisory_count": 47,
"version_mapped_advisory_count": 20,
"first_advisory_at": "2024-07-09T19:34:07+00:00",
"latest_advisory_at": "2026-03-23T18:56:07+00:00",
"latest_advisory_at": "2026-03-27T20:49:46+00:00",
"advisory_ids": [
"traefik--05879db0a0",
"traefik--073109115e",
@@ -71,6 +71,8 @@
"traefik--CVE-2026-29777",
"traefik--CVE-2026-32305",
"traefik--CVE-2026-32595",
"traefik--CVE-2026-32695",
"traefik--CVE-2026-33433",
"traefik--GHSA-4hjq-9h5c-252j",
"traefik--GHSA-5423-jcjm-2gpv",
"traefik--GHSA-gv8r-9rw9-9697",

查看文件

@@ -22,7 +22,7 @@
],
"version_sync_status": "green",
"security_version_count": 4,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q"

查看文件

@@ -32,7 +32,7 @@
],
"version_sync_status": "green",
"security_version_count": 21,
"last_version_synced_at": "2026-03-27T09:30:51+00:00",
"last_version_synced_at": "2026-03-28T09:18:16+00:00",
"latest_version_evidence": [
"npm latest",
"https://github.com/nodejs/undici/security/advisories/GHSA-3cvr-822r-rqcc",

某些文件未显示,因为此 diff 中更改的文件太多 显示更多