Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

🔒 [IBM OSPO Security Notification] — IBM/AssetOpsBench

Aperta
#580 9 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
25/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
cryptography, github, python
Ambito
devops, security

Direzione di ricerca

Start by locating the repository's dependency manifests and reviewing the unresolved Dependabot alerts listed here, while checking linked PRs 570–574 to avoid duplicating work. Update or otherwise remediate the remaining vulnerable dependencies, then verify that the security alerts are resolved; the issue is done when all listed alerts are cleared.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

security

🔒 [IBM OSPO Security Notification] — IBM/AssetOpsBench

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @ShuxinLin @DhavalRepo18

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟠 high CVE-2026-97687 urllib3 >= 1.26.0, < 2.8.0 2.8.0 2026-11-01 PR
🟠 high CVE-2026-97689 urllib3 >= 1.10.3, < 2.8.0 2.8.0 2026-11-01 PR
🟠 high CVE-2026-80047 transformers >= 4.49.0, <= 5.8.1 — 2026-11-01 —
🟠 high GHSA-c2m8-h5v5-343r tornado <= 6.5.8 6.5.9 2026-11-01 PR
🟠 high GHSA-chx6-46f5-w4vp tornado <= 6.5.8 6.5.9 2026-11-01 PR
🟠 high CVE-2026-102831 jupyterlab >= 4.6.0, <= 4.6.3 4.6.4 2026-11-01 PR
🟠 high CVE-2026-104873 langgraph-sdk >= 0.1.45, <= 0.4.3 0.4.4 2026-11-06 PR
🟠 high CVE-2026-104851 fsspec >= 0.9.0, < 2026.6.0 2026.6.0 2026-11-06 PR
🟡 medium CVE-2026-84377 litellm >= 1.94.0, < 1.94.3 1.94.3 2026-12-31 —
🟡 medium CVE-2026-97688 urllib3 >= 2.6.2, < 2.8.0 2.8.0 2026-12-31 PR
🟡 medium GHSA-3hv7-mjh2-fv65 tornado <= 6.5.8 6.5.9 2026-12-31 PR
🟡 medium CVE-2026-102904 jupyterlab >= 4.6.0, <= 4.6.3 4.6.4 2026-12-31 PR
🟡 medium CVE-2026-102830 jupyterlab >= 4.6.0, <= 4.6.3 4.6.4 2026-12-31 PR
🟡 medium CVE-2026-66007 datasets < 5.0.1 5.0.1 2027-01-02 PR
🟡 medium CVE-2026-104874 multidict >= 6.7.0, <= 6.9.0 6.9.1 2027-01-05 PR
Code Scanning Alerts
Severity Rule Tool Deadline
🟡 medium actions/missing-workflow-permissions CodeQL 2026-12-28
Secret Scanning Alerts

No open secret scanning alerts.


Lingua principale
Python
Stelle
2.3k
Fork
332
Merge medio
13h 6m
PR unite (30g)
33

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di IBM/AssetOpsBench

Tutte le issue di IBM/AssetOpsBench

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.