Skip to content
CloseYourItdocsPages

Documentation / Using CloseYourIt

Vulnerabilities

Known security problems in your projects' libraries, and the languages that no longer get fixes.

Every night CloseYourIt reads the list of libraries of each project connected to a repository and compares it with the public database of known security problems (OSV.dev). The Vulnerabilities page tells you what is affected, how serious it is and which version to update to.

Turn on the check

  1. Connect the GitHub repository to the project (see GitHub). Nothing to install in your code.
  2. Wait for the nightly check, or press Check now on the page to get one right away.

What it checks

Libraries. The files that pin library versions, wherever they are in the repository:

LanguageFile
RubyGemfile.lock
JavaScriptpnpm-lock.yaml, package-lock.json
Flutter and Dartpubspec.lock
Gogo.sum

Libraries pulled in by other libraries count too: in the list they are marked Indirect, the others Direct. Folders holding copies of libraries, such as node_modules and vendor, are not read.

Languages. The versions declared in mise.toml, .tool-versions or .ruby-version: Ruby, Node.js, Python, Go and PostgreSQL. End-of-support dates come from endoflife.date. A version is Supported, Ending soon or End of life.

Read the page

At the top, the counts: Open, Open critical, Open high, Ignored, the languages at End of life and the Last scan.

Two tabs:

  • Libraries: library, severity, database reference, the version that fixes it (Fixed in), project, file and when it was seen. A click opens the description and links to read more.
  • Languages: version in use, latest version and end-of-support date.

Severity comes from the public database: Low, Moderate, High, Critical. Unclassified means nobody has assessed its weight yet.

Decide what to do

  • Open ticket creates a ticket for the vulnerability (see Tickets).
  • Ignore sets it aside if you choose to live with the risk. It does not reopen by itself at later checks. Reopen puts it back on the list.
  • When you update the library, the next check marks it Resolved by itself.

If it says No fixed version, no version fixes it yet: ignore it until one comes out, or open a ticket to replace the library.

Alerts and automatic tickets

  • Every new vulnerability sends an alert to whoever receives it (see Alerts).
  • High and Critical vulnerabilities also open a ticket by themselves. Unclassified ones do not: you open the ticket when you decide to act.

When a file cannot be read

If a library file cannot be read, the page says Incomplete check. Known vulnerabilities from that file stay on the list: they disappear only after a successful read proves they are gone.