# Project Safe Source: Identifying potential vulnerabilities in Wolfi upstream

DevFeed: [Project Safe Source: Identifying potential vulnerabilities in Wolfi upstream](<https://devfeed.tech/articles/project-safe-source-identifying-potential-vulnerabilities-in-wolfi-upstream-13204.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/project-safe-source-identifying-potential-vulnerabilities-in-wolfi-upstream>)

Author: About the Author

Published: 2024-08-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Code](<https://devfeed.tech/topics/code.md>), [Bot](<https://devfeed.tech/topics/bot.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [code](<https://devfeed.tech/tags/code.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [project](<https://devfeed.tech/tags/project.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

Chainguard's Project Safe Source used CodeQL to scan more than 1,000 open source projects packaged in Wolfi. The scan identified seven classes of potential vulnerabilities across 226 projects, totaling 1,878 alerts, and highlighted candidates for automated pull requests.

## Source excerpt

Chainguard's Project Safe Source uses CodeQL to identify & fix vulnerabilities in open source projects packaged in Wolfi with automated pull requests.