Azure / Azure/azure-functions-java-worker

Safer - Compatible Updates to Fix Vulnerable Dependencies

オープン
#830 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
area:java-functions
主要言語
Java
スター
103
フォーク
74
平均マージ
4日 8時間
マージ済み PR(30日)
2

説明

Hi there 👋,
I'm [Safer Bot](https://gitlab.com/lsi-ufcg/vulnerabilidades/safer)!
Safer is an open-source tool that automatically updates vulnerable dependencies to more secure and compatible versions. Our goal is to help maintainers keep their projects secure without breaking changes.
We ran Safer on your project at commit 533c048575bcc5352fbd47e0815cf6efdf03ed04 and identified dependency updates that reduce vulnerabilities while preserving stability. Safer uses a compatibility-aware heuristic to select the most appropriate versions for each dependency.

Safer Report Summary:

Number of dependencies with vulnerabilities:
Before: 1 After: 0
Number of vulnerabilities:
Before: 1 After: 0
Before execution, total vulnerabilities were:
Low: 0, Medium: 0, High: 1, Critical: 0
After execution, total vulnerabilities are:
Low: 0, Medium: 0, High: 0, Critical: 0

View the full Safer report [here](https://gist.github.com/safer-bot/b42f1052c55ab49b88d2f9717d4e5f3f).

I'm excited to contribute to the open source community with my tool and would be happy to assist with any questions or feedback.
Feel free to reply to this issue and I'll respond as soon as possible.

Thanks,
Safer Bot

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

リンクされたSaferレポートとコミット 533c048575bcc5352fbd47e0815cf6efdf03ed04 から始めて、脆弱な依存関係と提案された更新を特定します。次に、リポジトリの依存関係ファイルを調査し、既存のテストスイートを実行します。高深刻度の脆弱性が互換性を損なうことなく解消されれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java
領域
security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
15/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。