apache / apache/cloudberry-pxf

Should we fix the `critical` or `high` issues reported by Dependabot alerts?

Open
#135 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
12
Forks
14
Avg merge
20h 35m
Merged PRs (30d)
9

Description

There are some critical or high security issues reported in the Dependabot alert.

Should we create PRs by clicking on the Create Security Update button instead of manually?

cc @MisterRaindrop @ostinru

Contributor guide

Open the contributing guide

Research direction

Review the critical and high Dependabot alerts first, then inspect the available Create Security Update workflow. Confirm whether updates should be opened through Dependabot or manually, and use the discussion to define the agreed follow-up; the issue names no files or tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.