Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

🔒 [IBM OSPO Security Notification] — IBM/CodeEngine

Abierto
#493 1 comentario 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
30/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Área
security

Línea de trabajo

This is a security notification from IBM OSPO about dependency vulnerabilities. The alerts involve the 'accelerate' and 'cookie' packages. Check the project's dependency files (like package.json, requirements.txt, or similar) to see where these packages are used. The goal is to update or replace the vulnerable packages to meet the specified SLAs. The issue provides deadlines but no specific code pointers; start by locating the dependency declarations and understanding the project's build and test process.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

security

🔒 [IBM OSPO Security Notification] — IBM/CodeEngine

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @uwefassnacht @smoser-ibm @jeremiaswerner @reggeenr

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟡 medium CVE-2026-69112 accelerate <= 1.14.0 — 2026-12-22 —
Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Lenguaje dominante
Shell
Estrellas
117
Forks
153
Merge medio
2 d 20 h
PR fusionados (30 d)
17

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de IBM/CodeEngine

Todos los issues de IBM/CodeEngine

Issues similares

Más issues de Shell/Bash

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.