Skip to content
Repository security report

Security report for medusajs/medusa

We found and prepared one improvement, and reviewed the public workflows for other areas worth hardening. Below: what we prepared, the other categories we found and what they mean, and how to request the fixes. We replaced changeable third-party workflow references with fixed versions, reducing the risk of unexpected upstream changes.

medusajs/medusa

7 references hardened

Delivered in PR #15664

Merged

Merged by the repository maintainers.

Other reviews available

Org-wide Actions hardening

The same pinning across your other public repositories.

Dependency vulnerability review

Review public dependency manifests for actionable upgrade candidates.

Managed security-update maintenance

Keep updates from becoming a backlog. Learn more.

Request the fixes for this repository

Want us to prepare the rest as reviewable pull requests? Submit your work email and we will confirm useful scope. We can also manage the resulting security-update PRs and repair failed updates. Nothing is opened or changed automatically.

This records your interest in a follow-on review. It does not prove repository-owner authorization, open anything on the repository, or start payment. A person confirms identity and useful scope before any further work.

Public repositories only unless explicitly authorized. Sensitive findings are handled privately. See Security Hardening for details.