Skip to content

CPAN-Security projects

Search results

  • Tooling for creating and managing standard SBOM objects like OWASP CycloneDX and SPDX, using both existing and new CPAN metadata.
    #1 updated Sep 30, 2025
  • Tasks related to content production, publication, community coordination, social media and other outreach efforts. Also, managing and keeping the CPANSec web presence up-to-date and useful, and integration with existing websites and services like MetaCPAN.
    #12 updated Sep 17, 2025
  • Standardization and publishing of CPAN package vulnerabilities in relevant indexes
    #10 updated Sep 17, 2025
  • For assisting, tracking and responding to legal and standardization issues and preparations around CPAN users and authors, including compliance with GDPR, NIS2 and other relevant regulations
    #9 updated Sep 17, 2025
  • Security Group Charter, Accountability, and Funding, including other internal policy-related topics.
    #7 updated Sep 15, 2025
  • Develop tooling for publishing and applying third-party security patches to CPAN distributions that have non-responsive authors, to enable high-priority updates to CPAN packages.
    #11 updated Jul 16, 2025
  • Establishing a trusted publishing infrastructure, including tooling and integration with https://in-toto.io/ and SLSA, and required Authentication regimes
    #3 updated Apr 8, 2025
  • Tooling for external (third-party) monitoring of updates to ecosystem packages, and tooling for fist-party integrity checking of metadata (e.g. sigstore or sigsum). See also https://transparency.dev
    #2 updated Apr 8, 2025