Skip to main content
Superblocks excludes a small set of npm packages from CVE detection. These packages ship in Superblocks templates. Superblocks has reviewed the known advisories against them and determined they are not exploitable on this platform, and Superblocks cannot upgrade the package today, or no upgrade exists. An excluded package does not block an install, does not produce a publish finding, and does not appear in Security Center. Superblocks maintains the list, and it applies to every organization. Each exception is scoped to one package and one advisory.

Why a package is excluded

Both of these must be true: The list is not a place to hide every noisy CVE. It exists so template packages that fail those two tests do not block every new app.

When an exception is removed

An exception is not permanent. Superblocks removes it when either condition no longer holds, most often when a patched version ships and Superblocks can upgrade the template. Once an exception is removed, the advisory behaves like any other finding. It blocks new installs of affected versions, appears at publish time under the policy’s scan mode, and surfaces in Security Center for published apps already on an affected version. If it is critical or high, it also triggers CVE notifications.

Requesting a change

Exceptions are managed by Superblocks and cannot be edited per organization. There is no way to add your own exception, and no way to opt out of one. If you believe a template package should be excluded, or that an exclusion no longer applies, contact Superblocks support with the advisory ID and the affected package. To accept the risk of a specific finding on a specific app instead, publish under Blocking with exceptions and use Publish anyway, which records the decision in the audit log. See How findings work.