Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

🔒 [IBM OSPO Security Notification] — IBM/CodeEngine

已关闭
#488 6 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
缺陷
描述清晰度
需要澄清
活跃度
活跃
领域
security

调研方向

先阅读 Security Issue Guide,然后定位 accelerate(受影响版本截至 1.14.0)和 cookie(受影响版本低于 0.7.0)的依赖声明。检查是否存在已批准的修补版本或其他补救路径,并且只有在列出的警报均已解决且 issue 可以自动关闭时,才认为工作已完成。

由索引模型根据 Issue 内容生成。

描述

security

🔒 [IBM OSPO Security Notification] — IBM/CodeEngine

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.

💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.

📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @uwefassnacht @smoser-ibm @jeremiaswerner @reggeenr

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟡 medium CVE-2026-69112 accelerate <= 1.14.0 — 2026-12-14 —
Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


主要语言
Shell
星标
117
派生
153
平均合并
2 天 20 小时
30 天内合并 PR
17

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

IBM/CodeEngine 的其他 Issue

查看 IBM/CodeEngine 的全部 Issue

相似的 Issue

更多 Shell/Bash Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。