π [IBM OSPO Security Notification] β IBM/project-documentation-template
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 65/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- javascript
- Domain
- security
Research direction
Start with the linked Security Issue Guide, then review the six Dependabot alerts and the listed patched versions for svgo, js-yaml, colord, and joi. Update the affected dependencies through the repository's dependency workflow and verify that all alerts are resolved; the issue should then close automatically.
Written by the indexing model from the issue text.
Description
π Security Alerts β IBM/project-documentation-template
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: (no direct admin collaborators assigned to this repo β please add an admin to receive security notifications)
Dependabot Alerts
| Severity | CVE/GHSA | Package | Affected | Patched | Fix PR |
|---|---|---|---|---|---|
| π high | CVE-2026-84370 | svgo | >= 3.0.0, < 3.3.5 | 3.3.5 | β |
| π high | CVE-2026-84375 | js-yaml | >= 3.0.0, < 3.15.2 | 3.15.2 | β |
| π‘ medium | CVE-2026-84369 | svgo | >= 3.0.0, < 3.3.5 | 3.3.5 | β |
| π‘ medium | CVE-2026-85062 | colord | < 2.9.4 | 2.9.4 | β |
| π΅ low | CVE-2026-84367 | joi | >= 16.0.0, < 17.13.5 | 17.13.5 | β |
| π΅ low | CVE-2026-84368 | joi | >= 17.2.0, < 17.13.6 | 17.13.6 | β |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
- Dominant language
- JavaScript
- Stars
- 4
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up β it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
HarperFast/skills#96 Β·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Automattic/studio#4908 Β·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
sugarlabs/musicblocks#8847 Β·
-
client-controller-update ta-bot-triage team-money-movement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
MetaMask/metamask-mobile#36594 Β·