| security.metacpan.org
The 2-argument open function is insecure| security.metacpan.org
Here is the CPANSec 2024 Retrospective| security.metacpan.org
The CPAN Security Group was authorized by the CVE Program as a CVE Numbering Authority (CNA) on Feb 25, 2025. A CNA assigns and manages CVE identifiers for projects in their scope.| security.metacpan.org
Adding a SECURITY or SECURITY.md file to your Perl distributions will let people know how to contact the maintainers if they find a security issue with your software...| security.metacpan.org
Any secret token that allows someone to access a resource or perform an action should be generated with a secure random number generator...| security.metacpan.org
Some end of year reminders for CPAN Authors: Do all of your modules have up-to-date contact information?| security.metacpan.org
CVE-2024-45321: In its default configuration cpanminus uses insecure HTTP to download and install code from CPAN. This results in a CWE-494 weakness, enabling code execution for network attackers.| security.metacpan.org
Between Dec 2023 and Jan 2024, vulnerabilities in Spreadsheet::ParseExcel and Spreadsheet::ParseXLSX were reported to the CPAN Security Group (CPANSec). This document describes the timeline and analysis of events.| security.metacpan.org
There’s a new group in the Perl + CPAN communities!| security.metacpan.org