Swift
20advisories edited11packagesRSS
An advisory is the GitHub security advisory a Dependabot alert links to. Each row is one change to one package.
No percentage: we don't know how many of the 35,259 compared advisories were Swift.
20 changes in this one line · newest first
One change, in full: Advisory: package added: 11 packages named as affected in Swift. The same change, 20 advisories. Back to Swift
| Package | Change | Advisory | What changed | Severity | Advisory published |
|---|---|---|---|---|---|
| github.com/vapor/leaf-kit | Package added | GHSA-6jj5-j4j8-8473CVE-2026-28499 | added as affected | moderate | 2026-03-16 |
| github.com/vapor/leaf-kit | Package added | GHSA-4hfh-fch3-5q7pCVE-2026-27120 | added as affected | moderate | 2026-02-19 |
| github.com/pytorch/executorch | Package added | GHSA-84m3-f99p-cqx5CVE-2025-30405 | added as affected | critical | 2025-08-08 |
| github.com/pytorch/executorch | Package added | GHSA-9m39-3mf3-xwchCVE-2025-54949 | added as affected | critical | 2025-08-08 |
| github.com/pytorch/executorch | Package added | GHSA-f9hx-c6jf-3qxmCVE-2025-54950 | added as affected | critical | 2025-08-08 |
| github.com/pytorch/executorch | Package added | GHSA-hj95-mhgf-jxc4CVE-2025-30404 | added as affected | critical | 2025-08-08 |
| github.com/pytorch/executorch | Package added | GHSA-xc7w-r669-48pfCVE-2025-54951 | added as affected | critical | 2025-08-08 |
| github.com/pytorch/executorch | Package added | GHSA-h952-963h-rv99CVE-2025-30402 | added as affected | high | 2025-07-11 |
| github.com/vapor/vapor | Package added | GHSA-r6r4-5pr8-gjcpCVE-2024-21631 | added as affected | moderate | 2024-01-03 |
| github.com/pubnub/swift | Package added | GHSA-5844-q3fc-56rhCVE-2023-26154 | added as affected | moderate | 2023-12-06 |
| github.com/apple/swift-nio-http2 | Package added | GHSA-qppj-fm5r-hxr3CVE-2023-44487 | added as affected | moderate | 2023-10-10 |
| github.com/vapor/vapor | Package added | GHSA-3mwq-h3g6-ffhmCVE-2023-44386 | added as affected | moderate | 2023-10-05 |
| github.com/weichsel/zipfoundation | Package added | GHSA-c2cc-3569-6jh2CVE-2023-39138 | added as affected | high | 2023-08-31 |
| github.com/marmelroy/zip | Package added | GHSA-g454-wj9r-jpg4CVE-2023-39135 | added as affected | high | 2023-08-31 |
| github.com/mongodb/mongo-swift-driver | Package added | GHSA-vxvm-qww3-2fh7CVE-2021-32050 | added as affected | moderate | 2023-08-29 |
| github.com/migueldeicaza/swiftterm | Package added | GHSA-jq43-q8mx-r7mqCVE-2022-23465 | added as affected | high | 2023-07-14 |
| github.com/grpc/grpc-swift | Package added | GHSA-r6ww-5963-7r95CVE-2022-24777 | added as affected | high | 2023-06-09 |
| github.com/apple/swift-nio-http2 | Package added | GHSA-q36x-r5x4-h4q6CVE-2022-0618 | added as affected | high | 2023-06-09 |
| github.com/apple/swift-nio-http2 | Package added | GHSA-ccw9-q5h2-8c2wCVE-2022-24666 | added as affected | high | 2023-05-18 |
| github.com/vapor/postgres-nio | Package added | GHSA-9cfh-vx93-84vvCVE-2023-31136 | added as affected | low | 2023-05-10 |
Dates are when the advisory was published, not when the change was seen.
An advisory not listed here had no change we could see; edits made before it reached the public mirror are invisible.
2 Swift advisories also had a severity change or were withdrawn (not in the counts above)
A severity change or a withdrawal applies to the whole advisory, not to a package, so it has no ecosystem. These 2 are here because the same advisory also names a Swift package in the table above; the other 3,178 of the 3,180 cannot be placed in an ecosystem at all.
| Change | Advisory | What changed | Severity | Advisory published |
|---|---|---|---|---|
| Severity changed | GHSA-c2cc-3569-6jh2CVE-2023-39138 | was MODERATE, now HIGH | high | 2023-08-31 |
| Severity changed | GHSA-g454-wj9r-jpg4CVE-2023-39135 | was MODERATE, now HIGH | high | 2023-08-31 |
Data sources and quality
Not checked: GitHub-reviewed advisories only. An advisory GitHub never reviewed, and an ecosystem it does not review, produce no row at all, so an ecosystem missing from these figures is not evidence that its advisories held.
Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.