Security report for medusajs/medusa
We found and prepared one improvement, and reviewed the public workflows for other areas worth hardening. Below: what we prepared, the other categories we found and what they mean, and how to request the fixes. We replaced changeable third-party workflow references with fixed versions, reducing the risk of unexpected upstream changes.
Merged by the repository maintainers.
Other reviews available
The same pinning across your other public repositories.
Review public dependency manifests for actionable upgrade candidates.
Keep updates from becoming a backlog. Learn more.
Request the fixes for this repository
Want us to prepare the rest as reviewable pull requests? Submit your work email and we will confirm useful scope. We can also manage the resulting security-update PRs and repair failed updates. Nothing is opened or changed automatically.
Public repositories only unless explicitly authorized. Sensitive findings are handled privately. See Security Hardening for details.