Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

🔒 [IBM OSPO Security Notification] — IBM/ELM-Python-Client

未關閉
#147 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
5/5
預估耗時
一週以上
新手友好度
25/100
Issue 類型
缺陷
描述清晰度
需要釐清
活躍度
活躍
技術堆疊
javascript, python
領域
security

研究方向

Start by opening the CodeQL alerts for py/clear-text-logging-sensitive-data, py/redos, js/functionality-from-untrusted-source, and js/incomplete-sanitization; the issue does not identify affected files or tests. Review each alert's CodeQL location and guidance, then verify that every listed alert is resolved and the security issue closes automatically.

由索引模型根據 Issue 內容生成。

描述

security

🔒 [IBM OSPO Security Notification] — IBM/ELM-Python-Client

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @barny

Dependabot Alerts

No open Dependabot alerts.

Code Scanning Alerts
Severity Rule Tool Deadline
🟠 high py/clear-text-logging-sensitive-data CodeQL 2026-10-29
🟠 high py/clear-text-logging-sensitive-data CodeQL 2026-10-29
🟠 high py/clear-text-logging-sensitive-data CodeQL 2026-10-29
🟠 high py/clear-text-logging-sensitive-data CodeQL 2026-10-29
🟠 high py/redos CodeQL 2026-10-29
🟠 high py/redos CodeQL 2026-10-29
🟡 medium js/functionality-from-untrusted-source CodeQL 2026-12-28
🟡 medium js/functionality-from-untrusted-source CodeQL 2026-12-28
🟡 medium js/functionality-from-untrusted-source CodeQL 2026-12-28
🟡 medium js/functionality-from-untrusted-source CodeQL 2026-12-28
🟡 medium js/functionality-from-untrusted-source CodeQL 2026-12-28
🟡 medium js/functionality-from-untrusted-source CodeQL 2026-12-28
🟡 medium js/functionality-from-untrusted-source CodeQL 2026-12-28
🟡 medium js/incomplete-sanitization CodeQL 2026-12-28
Secret Scanning Alerts

No open secret scanning alerts.


主要語言
HTML
星號
52
分支
32
PR 合併指標
30 天內沒有已合併 PR

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

IBM/ELM-Python-Client 的其他 Issue

查看 IBM/ELM-Python-Client 的全部 Issue

相似的 Issue

更多 Security Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。