Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

🔒 [IBM OSPO Security Notification] — IBM/secrets-manager-java-sdk

Offen
#210 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Anfängerfreundlichkeit
55/100
Issue-Typ
Bug
Klarheit
Größtenteils klar
Aktivitätsstatus
Aktiv
Tech-Stack
java, javascript
Bereich
security

Rechercherichtung

Review the Dependabot alerts and locate the dependency manifest or lockfile containing ip-address and undici. Update each affected package to the listed patched version, then run the repository's available dependency checks and confirm that all six alerts are resolved.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

security

🔒 [IBM OSPO Security Notification] — IBM/secrets-manager-java-sdk

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @IdanAdar @secrets-automation-dev

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟠 high CVE-2026-69192 ip-address <= 10.3.0 10.3.1 2026-10-30 —
🟡 medium CVE-2026-54272 ip-address >= 10.1.1, <= 10.2.0 10.2.1 2026-12-29 —
🟡 medium CVE-2026-69198 ip-address >= 10.1.1, <= 10.2.1 10.2.2 2026-12-29 —
🟡 medium CVE-2026-16728 undici < 6.28.0 6.28.0 2026-12-29 —
🟡 medium CVE-2026-15157 undici < 6.28.0 6.28.0 2026-12-29 —
🟡 medium CVE-2026-16729 undici < 6.28.0 6.28.0 2026-12-29 —
🟡 medium CVE-2026-101910 ip-address >= 10.2.0, <= 10.5.0 10.5.1 2026-12-28 —
🟡 medium CVE-2026-101913 ip-address <= 10.5.0 10.5.1 2026-12-29 —
🟡 medium CVE-2026-102277 brace-expansion >= 4.0.0, < 5.0.12 5.0.12 2026-12-29 —
🟡 medium CVE-2026-101912 ip-address <= 10.7.0 10.7.1 2026-12-29 —
🔵 low CVE-2026-18540 undici < 6.28.1 6.28.1 — —
Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Vorherrschende Sprache
Java
Sterne
2
Forks
8
Ø Merge
5 T. 11 Std.
Gemergte PRs (30 T.)
11

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus IBM/secrets-manager-java-sdk

Alle Issues in IBM/secrets-manager-java-sdk

Ähnliche Issues

Weitere Issues zu Java

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.