Sync the CVE/GHSA advisories from WordPress core to this project.
The project already syncs tags. Would it be possible to include these advisories?
The reason for doing this would be:
- Advisories would surface when a project contains the
johnpbloch/wordpress dependency, and Composer runs its audit functionality.
- Versions marked with the vulnerability as fixed would bypass any cooldown values set in Dependabot/Renovate, allowing security releases to be integrated more quickly.
- Allow advanced projects to run fully automated upgrades while taking advantage of Composer
Sync the CVE/GHSA advisories from WordPress core to this project.
The project already syncs tags. Would it be possible to include these advisories?
The reason for doing this would be:
johnpbloch/wordpressdependency, and Composer runs its audit functionality.