Skip to content

CPAN-Security projects

Search results

  • #12 updated Apr 3, 2025
    Tasks related to content production, publication, community coordination, social media and other outreach efforts. Also, managing and keeping the CPANSec web presence up-to-date and useful, and integration with existing websites and services like MetaCPAN.
  • Work on tooling for analyzing and detecting packages and dependencies for known vulnerabilities
  • #3 updated Mar 22, 2025
    Establishing a trusted publishing infrastructure, including tooling and integration with https://in-toto.io/ and SLSA, and required Authentication regimes
  • Tooling for external (third-party) monitoring of updates to ecosystem packages, and tooling for fist-party integrity checking of metadata (e.g. sigstore or sigsum). See also https://transparency.dev
  • #1 updated Feb 27, 2025
    Tooling for creating and managing standard SBOM objects like OWASP CycloneDX and SPDX, using both existing and new CPAN metadata.
  • #11 updated Feb 27, 2025
    Develop tooling for publishing and applying third-party security patches to CPAN distributions that have non-responsive authors, to enable high-priority updates to CPAN packages.
  • #15 updated Feb 27, 2025
    Tracking efforts to be secure by default in the CPAN and Perl communities
  • #9 updated Feb 27, 2025
    For assisting, tracking and responding to legal and privacy issues around CPAN metadata, including compliance with GDPR, NIS2 and other relevant regulations
  • #7 updated Feb 25, 2025
    Security Group Charter, Accountability, and Funding, including other Policy-related topics.
  • #10 updated Feb 25, 2025
    Standardization and publishing of CPAN package vulnerabilities in relevant indexes