Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

🔒 [IBM OSPO Security Notification] — IBM/simrun

Aperta
#72 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
30/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
docker, go, vite

Direzione di ricerca

The issue lists multiple dependency vulnerabilities with deadlines. Check the project's dependency files (like go.mod, package.json, or lockfiles) to see current versions. For vite and postcss, a fix PR #70 exists; review it to understand the update. For docker and other packages, check if updates are available. Running dependency audits and tests after updates is needed to confirm resolution.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

security

🔒 [IBM OSPO Security Notification] — IBM/simrun

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @faloker

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟠 high CVE-2026-41567 github.com/docker/docker <= 28.5.2 — 2026-10-26 —
🟠 high CVE-2026-42306 github.com/docker/docker <= 28.5.2 — 2026-10-26 —
🟠 high CVE-2026-53571 vite >= 8.0.0, <= 8.0.15 8.0.16 2026-10-26 PR
🟠 high CVE-2026-73646 postcss <= 8.5.17 8.5.18 2026-10-26 —
🟡 medium CVE-2026-33997 github.com/docker/docker < 29.3.1 — 2026-12-25 —
🟡 medium CVE-2026-41568 github.com/docker/docker <= 28.5.2 — 2026-12-25 —
🟡 medium CVE-2026-53632 vite >= 8.0.0, <= 8.0.15 8.0.16 2026-12-25 PR
🟡 medium GHSA-866w-xmhq-wj7x @sveltejs/kit <= 2.69.0 2.69.1 2026-12-25 —
🟡 medium CVE-2026-69153 postcss <= 8.5.22 8.5.23 2026-12-25 —
🔵 low CVE-2024-47764 cookie < 0.7.0 0.7.0 — —
Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Lingua principale
Go
Stelle
10
Fork
1
Merge medio
13m
PR unite (30g)
2

Preparare l'ambiente

  • Include un Dockerfile o un file Docker Compose
  • Nessun modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di IBM/simrun

Tutte le issue di IBM/simrun

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.