I got an email from Vercel urging to upgrade Next.js based project 3 days ago. POC was published 2 days ago. Today I’ve checked my logs and I could already see attack attempts.

  • Gamma@beehaw.org
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    1 day ago

    Renovate can flag CVEs in its pull requests, if you just want to check versions