Live data from GitHub and npm, updated daily.
Data last fetched: 2026-06-29
2 active CVEs reported via OSV.dev
DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
Rollup 4 has Arbitrary File Write via Path Traversal
Get SLA-backed support, security patches, and direct access to senior engineers for Rollup — without relying on volunteer maintainers.