kastle previously had zero CVE coverage (no package-lock.json parser). Parser fixed Jul 14 — this issue tracks triage of whatever the scan now reports: classify each finding runtime vs build-time, patch or document. Runtime CRITICALs escalate to P1 Proposal.
kastle previously had zero CVE coverage (no package-lock.json parser). Parser fixed Jul 14 — this issue tracks triage of whatever the scan now reports: classify each finding runtime vs build-time, patch or document. Runtime CRITICALs escalate to P1 Proposal.