Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

Package Drift Weekly — 2026-08-07

Automated weekly digest from pkgdrift — LLM-refined package intelligence across npm, PyPI, Cargo (Rust), and RubyGems. Pipeline runs every 6 hours. This Week's Signal 15 packages tracked across alpine, car

Automated weekly digest from pkgdrift — LLM-refined package intelligence across npm, PyPI, Cargo (Rust), and RubyGems. Pipeline runs every 6 hours.

This Week's Signal

15 packages tracked across alpine, cargo · 4 showing drift · 3 active advisories in the GitHub feed (5 hit a tracked package)

Package Ecosystem Version Drift Vulns Notes
apk-tools alpine 3.0.7 No 4 CVE(s)
brotli alpine 1.2.0 ⚠ Yes 1 CVE(s) Major-line .0 stalled 132d.
busybox alpine 1.38.0 No —
ca-certificates alpine 20260611 No —
dnssec-root alpine 20250524 ⚠ Yes — Last publish 433d ago.
harfbuzz alpine 14.2.1 No —
ldns alpine 1.9.2 No 2 CVE(s)
nghttp3 alpine 1.18.0 No —
ngtcp2 alpine 1.25.0 No —
nspr alpine 4.38.2 ⚠ Yes — Last publish 235d ago.
nss alpine 3.125 No —
openssl alpine 3.5.7 No 123 CVE(s)
sqlite alpine 3.53.4 No —
unbound alpine 1.25.2 No —
actix-codec cargo 0.5.2 ⚠ Yes 2 CVE(s) Last publish 919d ago.

Advisory Highlights

  • GHSA-957r-qf9p-67xw
  • GHSA-6hr6-w5qg-qmwg
  • GHSA-596p-6jv8-775v

Query via GET /v1/advisories.

How the Data Is Generated

Each record is fetched live from the package registry, cross-referenced against the GitHub Advisory Database, and refined by a local LLM that assigns a confidence score. Only records with confidence ≥ 0.6 reach the API.

Try It Free

Available at api.pkgdrift.com and on RapidAPI with a free tier (100 req/hr, no credit card).

curl -H "X-API-Key: YOUR_KEY" https://api.pkgdrift.com/v1/npm/express

Published automatically by the pkgdrift autonomous worker.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.