mend-for-github-com[bot]

Results 1661 issues of mend-for-github-com[bot]

Vulnerable Library - certifi-2024.6.2-py3-none-any.whl Python package for providing Mozilla's CA Bundle. Library home page: https://files.pythonhosted.org/packages/5b/11/1e78951465b4a225519b8c3ad29769c49e0d8d157a070f681d5b6d64737f/certifi-2024.6.2-py3-none-any.whl Path to dependency file: /requirements.txt Path to vulnerable library: /requirements.txt ## Vulnerabilities | CVE |...

Mend: dependency security vulnerability

## gnp-token-success.json - Base64 High Entropy String Violation detected in /test/Client/Credentials/Handler/Fixtures/Responses/gnp-token-success.json:[4-5] :page_with_curl: File Type: secrets :no_entry: Details - Base64 High Entropy String

Mend: IaC violation

Vulnerable Library - setuptools-65.6.3-py3-none-any.whl Easily download, build, install, upgrade, and uninstall Python packages Library home page: https://files.pythonhosted.org/packages/ef/e3/29d6e1a07e8d90ace4a522d9689d03e833b67b50d1588e693eec15f26251/setuptools-65.6.3-py3-none-any.whl Path to dependency file: /tmp/ws-scm/Aspect-Based-Sentiment-Analysis Path to vulnerable library: /tmp/ws-scm/Aspect-Based-Sentiment-Analysis Found in HEAD...

Mend: dependency security vulnerability

Vulnerable Library - zipp-3.11.0-py3-none-any.whl Backport of pathlib-compatible object wrapper for zip files Library home page: https://files.pythonhosted.org/packages/d8/20/256eb3f3f437c575fb1a2efdce5e801a5ce3162ea8117da96c43e6ee97d8/zipp-3.11.0-py3-none-any.whl Path to dependency file: /tmp/ws-scm/Aspect-Based-Sentiment-Analysis Path to vulnerable library: /tmp/ws-scm/Aspect-Based-Sentiment-Analysis,/.ws-temp-THFHIH-requirements.txt ## Vulnerabilities | Vulnerability...

Mend: dependency security vulnerability

Vulnerable Library - idna-3.4-py3-none-any.whl Internationalized Domain Names in Applications (IDNA) Library home page: https://files.pythonhosted.org/packages/fc/34/3030de6f1370931b9dbb4dad48f6ab1015ab1d32447850b9fc94e60097be/idna-3.4-py3-none-any.whl Path to dependency file: /tmp/ws-scm/Aspect-Based-Sentiment-Analysis Path to vulnerable library: /tmp/ws-scm/Aspect-Based-Sentiment-Analysis,/.ws-temp-THFHIH-requirements.txt Found in HEAD commit: d952432cb8d2cb53d7a0c189dc2d16fc535cdc75 ##...

Mend: dependency security vulnerability

Vulnerable Library - certifi-2024.6.2-py3-none-any.whl Python package for providing Mozilla's CA Bundle. Library home page: https://files.pythonhosted.org/packages/5b/11/1e78951465b4a225519b8c3ad29769c49e0d8d157a070f681d5b6d64737f/certifi-2024.6.2-py3-none-any.whl Path to dependency file: /requirements.txt Path to vulnerable library: /requirements.txt ## Vulnerabilities | CVE |...

Mend: dependency security vulnerability

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [aws-cdk-lib](https://redirect.github.com/aws/aws-cdk) ([source](https://redirect.github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib)) | dependencies | minor | [`2.45.0` -> `2.88.0`](https://renovatebot.com/diffs/npm/aws-cdk-lib/2.45.0/2.88.0) | By merging...

security fix

Vulnerable Library - parser-4.33.0.tgz Path to dependency file: /keycloak/package.json Path to vulnerable library: /nightly-playground/package.json Found in HEAD commit: ebb2ca86677193665d2206384ab65187178e01ad ## Vulnerabilities | CVE | Severity | CVSS | Dependency |...

Mend: dependency security vulnerability

Vulnerable Library - assets-1.204.0.tgz Path to dependency file: /keycloak/package.json Path to vulnerable library: /keycloak/package.json Found in HEAD commit: ebb2ca86677193665d2206384ab65187178e01ad ## Vulnerabilities | CVE | Severity | CVSS | Dependency |...

Mend: dependency security vulnerability

## CVE-2024-7254 - High Severity Vulnerability Vulnerable Library - protobuf-java-3.25.4.jar Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Library...

untriaged
Mend: dependency security vulnerability