7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether @hulumi/policies is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-82855
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
UNKNOWN
CVE-2026-82856
@hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators
UNKNOWN
CVE-2026-82860
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
UNKNOWN
CVE-2026-82861
@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass
UNKNOWN
CVE-2026-48033
@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
UNKNOWN
CVE-2026-48034
@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
UNKNOWN
CVE-2026-48032
@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes