mend-for-github-com[bot]

Results 1661 issues of mend-for-github-com[bot]

Vulnerable Library - certifi-2024.2.2-py3-none-any.whl Python package for providing Mozilla's CA Bundle. Library home page: https://files.pythonhosted.org/packages/ba/06/a07f096c664aeb9f01624f858c3add0a4e913d6c96257acb4fce61e7de14/certifi-2024.2.2-py3-none-any.whl Path to dependency file: /requirements.txt Path to vulnerable library: /requirements.txt Found in HEAD commit: e17699a1364a4f92ea96643d6ccea5c9157d5434...

Mend: dependency security vulnerability

Vulnerable Library - zipp-3.15.0-py3-none-any.whl Backport of pathlib-compatible object wrapper for zip files Library home page: https://files.pythonhosted.org/packages/5b/fa/c9e82bbe1af6266adf08afb563905eb87cab83fde00a0a08963510621047/zipp-3.15.0-py3-none-any.whl Path to dependency file: /requirements.txt Path to vulnerable library: /requirements.txt Found in HEAD commit:...

Mend: dependency security vulnerability

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [grunt-contrib-connect](https://redirect.github.com/gruntjs/grunt-contrib-connect) | dependencies | major | [`^3.0.0` -> `^4.0.0`](https://renovatebot.com/diffs/npm/grunt-contrib-connect/3.0.0/4.0.0) | By merging this...

security fix

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [grunt-contrib-connect](https://redirect.github.com/gruntjs/grunt-contrib-connect) | dependencies | major | [`^3.0.0` -> `^4.0.0`](https://renovatebot.com/diffs/npm/grunt-contrib-connect/3.0.0/4.0.0) | By merging this...

security fix

## metrics.yml - Ensure top-level permissions are not set to write-all Violation detected in /.github/workflows/metrics.yml:[0-1] :page_with_curl: File Type: github_actions :no_entry: Details - Ensure top-level permissions are not set to write-all

Mend: IaC violation

## metrics.yml - Ensure top-level permissions are not set to write-all Violation detected in /.github/workflows/metrics.yml:[0-1] :page_with_curl: File Type: github_actions :no_entry: Details - Ensure top-level permissions are not set to write-all

Mend: IaC violation

## ot.yml - Ensure top-level permissions are not set to write-all Violation detected in /.github/workflows/ot.yml:[0-1] :page_with_curl: File Type: github_actions :no_entry: Details - Ensure top-level permissions are not set to write-all

Mend: IaC violation

## CVE-2025-27622 - Medium Severity Vulnerability Vulnerable Library - jenkins-core-2.426.3.jar Jenkins core code and view files to render HTML. Library home page: https://github.com/jenkinsci/jenkins Path to dependency file: /build.gradle Path to...

Mend: dependency security vulnerability

## CVE-2025-27623 - Medium Severity Vulnerability Vulnerable Library - jenkins-core-2.426.3.jar Jenkins core code and view files to render HTML. Library home page: https://github.com/jenkinsci/jenkins Path to dependency file: /build.gradle Path to...

Mend: dependency security vulnerability

## CVE-2025-27624 - Medium Severity Vulnerability Vulnerable Library - jenkins-core-2.426.3.jar Jenkins core code and view files to render HTML. Library home page: https://github.com/jenkinsci/jenkins Path to dependency file: /build.gradle Path to...

Mend: dependency security vulnerability