Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

🔒 [IBM OSPO Security Notification] — IBM/CodeEngine

Aperta
#493 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
30/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Ambito
security

Direzione di ricerca

This is a security notification from IBM OSPO about dependency vulnerabilities. The alerts involve the 'accelerate' and 'cookie' packages. Check the project's dependency files (like package.json, requirements.txt, or similar) to see where these packages are used. The goal is to update or replace the vulnerable packages to meet the specified SLAs. The issue provides deadlines but no specific code pointers; start by locating the dependency declarations and understanding the project's build and test process.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

security

🔒 [IBM OSPO Security Notification] — IBM/CodeEngine

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @uwefassnacht @smoser-ibm @jeremiaswerner @reggeenr

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟡 medium CVE-2026-69112 accelerate <= 1.14.0 — 2026-12-22 —
Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Lingua principale
Shell
Stelle
117
Fork
153
Merge medio
2g 20h
PR unite (30g)
17

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di IBM/CodeEngine

Tutte le issue di IBM/CodeEngine

Issue simili

Altre issue su Shell/Bash

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.