Internet Explorer is no longer supported. Many things will still work, but your experience will be degraded and some things won't function. Please use a modern browser such as Edge, Chrome, or Firefox.

Welcome to Inedo Security Labs

Established in 2023, we are a team of security researchers focused on improving Software Supply Chain Security. We curate the ProGet Vulnerability Database (PGVD) and publish clear, practical write-ups to help teams understand real-world risk—not just theoretical severity.

To better prioritize that risk, we created the ProGet Vulnerability Remediation Scale (PVRS). Instead of relying on CVSS scores, PVRS uses simple categories to reflect real-world impact and urgency. It highlights what can be safely monitored versus what requires immediate action, including the most critical Category 5 vulnerabilities.

  • 191668
    Detected
    Vulnerabilities
  • 237030
    Malicious
    Packages
  • 20
    Category 5
    Vulnerabilties

Latest Vulnerabilities Detected

PVRS CategoryVulnerability IDSummaryPackage
PGV-2664640

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

djangorestframework, djangorestframework

PGV-2664639

nanoid: Integer Overflow or Wraparound

nanoid

PGV-2664638

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

pnpm

PGV-2664633

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

pnpm

PGV-2664635

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

@appium/base-driver

Meet the Inedo Security Labs Team

We're a small but focused team that reports directly to Inedo's CEO, Alex Papadimoulis. Our experience is diverse and over a range of domains and technologies, from Java in the banking sector to legacy Windows systems in mining, and advancements in cloud-native and machine learning. And although we're new to the Inedo team, we started with a ton of experience in Inedo's products.

Our Analysts

Pete Barnum
Senior Security Analyst
Pete has a background in regulatory compliance, with a focus on cybersecurity, SDLC auditing, risk management, disaster recovery, and IT vendor management. He's worked the Banking, Logistics, and Government sectors... but not yet the live/traveling entertainment industry.
Kim Pento
Chief Security Researcher
As Chief Security Researcher at Inedo Security Labs, Kim leverages her 20 years of expertise in cybersecurity in highly regulated sectors, oversees the team, and was a key figure alongside Alex Papadimoulis, CEO of Inedo, in the establishment of Inedo Security Labs.
Tod Hoven
Security Analyst
Tod is a former product engineer of ProGet transitioned into a career as a security researcher. Interested in analyzing and dissecting various software and systems to discover potential vulnerabilities and threats, vulnerability assessment, penetration testing, and threat modeling.