Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Safer - Compatible Updates to Fix Vulnerable Dependencies

Đang mở
#830 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
15/100
Loại issue
Lỗi
Độ rõ ràng
Cần làm rõ
Mức độ hoạt động
Đình trệ
Công nghệ
java
Lĩnh vực
security

Hướng nghiên cứu

Bắt đầu bằng báo cáo Safer được liên kết và commit 533c048575bcc5352fbd47e0815cf6efdf03ed04 để xác định dependency dễ bị tấn công và bản cập nhật được đề xuất. Sau đó, kiểm tra các tệp dependency của repository và chạy bộ kiểm thử hiện có; công việc được xem là hoàn tất khi lỗ hổng mức độ nghiêm trọng cao được loại bỏ mà không làm hỏng tính tương thích.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area:java-functions

Hi there 👋,
I'm Safer Bot!
Safer is an open-source tool that automatically updates vulnerable dependencies to more secure and compatible versions. Our goal is to help maintainers keep their projects secure without breaking changes.
We ran Safer on your project at commit 533c048575bcc5352fbd47e0815cf6efdf03ed04 and identified dependency updates that reduce vulnerabilities while preserving stability. Safer uses a compatibility-aware heuristic to select the most appropriate versions for each dependency.

Safer Report Summary:

Number of dependencies with vulnerabilities:
Before: 1 After: 0
Number of vulnerabilities:
Before: 1 After: 0
Before execution, total vulnerabilities were:
Low: 0, Medium: 0, High: 1, Critical: 0
After execution, total vulnerabilities are:
Low: 0, Medium: 0, High: 0, Critical: 0

View the full Safer report here.

I'm excited to contribute to the open source community with my tool and would be happy to assist with any questions or feedback.
Feel free to reply to this issue and I'll respond as soon as possible.

Thanks,
Safer Bot

Ngôn ngữ chính
Java
Star
103
Fork
74
Merge trung bình
1 ngày 11 giờ
Pull request đã merge (30 ngày)
3

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của Azure/azure-functions-java-worker

Tất cả issue của Azure/azure-functions-java-worker

Issue tương tự

Thêm issue về Java

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.