🔒 [IBM OSPO Security Notification] — IBM/CodeEngine
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 30/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Ambito
- security
Direzione di ricerca
This is a security notification from IBM OSPO about dependency vulnerabilities. The alerts involve the 'accelerate' and 'cookie' packages. Check the project's dependency files (like package.json, requirements.txt, or similar) to see where these packages are used. The goal is to update or replace the vulnerable packages to meet the specified SLAs. The issue provides deadlines but no specific code pointers; start by locating the dependency declarations and understanding the project's build and test process.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
🔒 [IBM OSPO Security Notification] — IBM/CodeEngine
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: @uwefassnacht @smoser-ibm @jeremiaswerner @reggeenr
Dependabot Alerts
| Severity | CVE/GHSA | Package | Affected | Patched | Deadline | Fix PR |
|---|---|---|---|---|---|---|
| 🟡 medium | CVE-2026-69112 | accelerate | <= 1.14.0 | — | 2026-12-22 | — |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
- Lingua principale
- Shell
- Stelle
- 117
- Fork
- 153
- Merge medio
- 2g 20h
- PR unite (30g)
- 17
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di IBM/CodeEngine
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
IBM/CodeEngine#494 · 1 commento ·
-
IBM/CodeEngine#321 · 2 commenti · 1 assegnatario ·
-
cos2cos missing Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 45/100
IBM/CodeEngine#141 · 6 commenti ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
IBM/CodeEngine#115 · 1 reazione ·
-
Add Build script to samples Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
IBM/CodeEngine#114 ·
Tutte le issue di IBM/CodeEngine
Issue simili
-
out-of-date
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
CachyOS/CachyOS-PKGBUILDS#1908 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
align on terminology Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
CycloneDX/transparency-exchange-api#393 · 1 commento ·
-
area:build bug good first issue sev:papercut
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
Agent-Field/CodeAF#1446 ·
-
module/agent platform/macos type/bug/regression
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100