apache / apache/cloudberry-pxf
Should we fix the `critical` or `high` issues reported by Dependabot alerts?
Open
- Dominant language
- Java
- Stars
- 12
- Forks
- 14
- Avg merge
- 20h 35m
- Merged PRs (30d)
- 9
Description
There are some critical or high security issues reported in the Dependabot alert.
Should we create PRs by clicking on the Create Security Update button instead of manually?
cc @MisterRaindrop @ostinru
Contributor guide
Research direction
Review the critical and high Dependabot alerts first, then inspect the available Create Security Update workflow. Confirm whether updates should be opened through Dependabot or manually, and use the discussion to define the agreed follow-up; the issue names no files or tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100