🔒 [IBM OSPO Security Notification] — IBM/MAX-Object-Detector
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
Research direction
Start with the linked Security Issue Guide and inspect the repository's Python dependency declarations for Pillow. Confirm the affected version range and the patched version 12.3.0, then verify that the Dependabot alert closes and the project still builds or tests successfully.
Written by the indexing model from the issue text.
Description
🔒 Security Alerts — IBM/MAX-Object-Detector
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: (no direct admin collaborators assigned to this repo — please add an admin to receive security notifications)
Dependabot Alerts
| Severity | CVE/GHSA | Package | Affected | Patched | Fix PR |
|---|---|---|---|---|---|
| 🟠 high | CVE-2026-59200 | Pillow | >= 5.1.0, < 12.3.0 | 12.3.0 | — |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
- Dominant language
- Python
- Stars
- 293
- Forks
- 222
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from IBM/MAX-Object-Detector
-
Docker build error Open
Difficulty 3/5 1-2 days Newbie friendliness 25/100
IBM/MAX-Object-Detector#181 · 1 comment ·
-
IBM/MAX-Object-Detector#163 · 3 comments · 1 assignee ·
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 45/100
IBM/MAX-Object-Detector#126 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 35/100
IBM/MAX-Object-Detector#115 ·
All issues in IBM/MAX-Object-Detector
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100