Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

🔒 [IBM OSPO Security Notification] — IBM/AssetOpsBench

Open
#580 9 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
cryptography, github, python
Domain
devops, security

Research direction

Start by locating the repository's dependency manifests and reviewing the unresolved Dependabot alerts listed here, while checking linked PRs 570–574 to avoid duplicating work. Update or otherwise remediate the remaining vulnerable dependencies, then verify that the security alerts are resolved; the issue is done when all listed alerts are cleared.

Written by the indexing model from the issue text.

Description

security

🔒 [IBM OSPO Security Notification] — IBM/AssetOpsBench

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @ShuxinLin @DhavalRepo18

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟠 high CVE-2026-97687 urllib3 >= 1.26.0, < 2.8.0 2.8.0 2026-11-01 PR
🟠 high CVE-2026-97689 urllib3 >= 1.10.3, < 2.8.0 2.8.0 2026-11-01 PR
🟠 high CVE-2026-80047 transformers >= 4.49.0, <= 5.8.1 — 2026-11-01 —
🟠 high GHSA-c2m8-h5v5-343r tornado <= 6.5.8 6.5.9 2026-11-01 PR
🟠 high GHSA-chx6-46f5-w4vp tornado <= 6.5.8 6.5.9 2026-11-01 PR
🟠 high CVE-2026-102831 jupyterlab >= 4.6.0, <= 4.6.3 4.6.4 2026-11-01 PR
🟠 high CVE-2026-104873 langgraph-sdk >= 0.1.45, <= 0.4.3 0.4.4 2026-11-06 PR
🟠 high CVE-2026-104851 fsspec >= 0.9.0, < 2026.6.0 2026.6.0 2026-11-06 PR
🟡 medium CVE-2026-84377 litellm >= 1.94.0, < 1.94.3 1.94.3 2026-12-31 —
🟡 medium CVE-2026-97688 urllib3 >= 2.6.2, < 2.8.0 2.8.0 2026-12-31 PR
🟡 medium GHSA-3hv7-mjh2-fv65 tornado <= 6.5.8 6.5.9 2026-12-31 PR
🟡 medium CVE-2026-102904 jupyterlab >= 4.6.0, <= 4.6.3 4.6.4 2026-12-31 PR
🟡 medium CVE-2026-102830 jupyterlab >= 4.6.0, <= 4.6.3 4.6.4 2026-12-31 PR
🟡 medium CVE-2026-66007 datasets < 5.0.1 5.0.1 2027-01-02 PR
🟡 medium CVE-2026-104874 multidict >= 6.7.0, <= 6.9.0 6.9.1 2027-01-05 PR
Code Scanning Alerts
Severity Rule Tool Deadline
🟡 medium actions/missing-workflow-permissions CodeQL 2026-12-28
Secret Scanning Alerts

No open secret scanning alerts.


Dominant language
Python
Stars
2.3k
Forks
332
Avg merge
13h 6m
Merged PRs (30d)
33

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from IBM/AssetOpsBench

All issues in IBM/AssetOpsBench

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.