Guide

Automatically patch vulnerable packages

Kristján Oddsson

Team + Vulnerability Patching and above

This guide shows you how to create a Vulnerability Patching policy so that vulnerable Homebrew formulae and casks, npm packages and VS Code extensions across your fleet are upgraded automatically. You need access to the Workbrew Console with permission to write Policies.

Create a Vulnerability Patching policy

  1. Navigate to the Policies page in the Workbrew Console
  2. Click New Policy
  3. Select Vulnerability Patching
  4. Set a minimum severity for Vulnerable Homebrew formulae
  5. Set a minimum severity for Vulnerable Homebrew casks
  6. Set a minimum severity for Vulnerable npm packages
  7. Set a minimum severity for Vulnerable VS Code extensions
  8. Click the Device Group dropdown to target a Device Group, or leave it as All Devices
  9. Click Enable Vulnerability Patching

Every source starts at Off, so set at least one of them to a severity. A policy saved with all sources left Off is created but patches nothing.

Each Device Group can only have one Vulnerability Patching policy, and a policy targeting All Devices counts as one too. The severity levels and the CVSS scores behind them are listed in Package vulnerabilities.

Confirm the policy is active

The policy appears on the Policies page with a badge for each source showing the threshold you chose, for example "Formulae ≥ High" and "Casks Off". The All threshold shows as "All updates".

Patching runs when a Device next checks in, not when you save the policy, so give the fleet a check-in cycle before expecting the Vulnerabilities page to change.

Update or remove the policy

  1. Navigate to the Policies page
  2. Click the Vulnerability Patching policy you want to change
  3. Adjust the thresholds or Device Group and click Save changes, or click Remove Vulnerability Patching

Removing the policy stops future patching. It does not roll back packages that have already been upgraded.