🔒 [IBM OSPO Security Notification] — IBM/MAX-Object-Detector

Open Beginner friendly
#195 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
68/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
python
Domain
security

Research direction

Start with the linked Security Issue Guide and inspect the repository's Python dependency declarations for Pillow. Confirm the affected version range and the patched version 12.3.0, then verify that the Dependabot alert closes and the project still builds or tests successfully.

Written by the indexing model from the issue text.

Description

security

🔒 Security Alerts — IBM/MAX-Object-Detector

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: (no direct admin collaborators assigned to this repo — please add an admin to receive security notifications)

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Fix PR
🟠 high CVE-2026-59200 Pillow >= 5.1.0, < 12.3.0 12.3.0
Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Dominant language
Python
Stars
293
Forks
222
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from IBM/MAX-Object-Detector

All issues in IBM/MAX-Object-Detector

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.