Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

🔒 [IBM OSPO Security Notification] — IBM/CodeEngine

未關閉
#493 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
30/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
活躍
領域
security

研究方向

This is a security notification from IBM OSPO about dependency vulnerabilities. The alerts involve the 'accelerate' and 'cookie' packages. Check the project's dependency files (like package.json, requirements.txt, or similar) to see where these packages are used. The goal is to update or replace the vulnerable packages to meet the specified SLAs. The issue provides deadlines but no specific code pointers; start by locating the dependency declarations and understanding the project's build and test process.

由索引模型根據 Issue 內容生成。

描述

security

🔒 [IBM OSPO Security Notification] — IBM/CodeEngine

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @uwefassnacht @smoser-ibm @jeremiaswerner @reggeenr

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟡 medium CVE-2026-69112 accelerate <= 1.14.0 — 2026-12-22 —
Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


主要語言
Shell
星號
117
分支
153
平均合併
2 天 20 小時
30 天內合併 PR
17

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

IBM/CodeEngine 的其他 Issue

查看 IBM/CodeEngine 的全部 Issue

相似的 Issue

更多 Shell/Bash Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。