atlassian / atlassian/jsm-integration-scripts
JiraEdgeConnector have several critical vulnerabilities.
Open
- Dominant language
- Python
- Stars
- 17
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Description
JiraEdgeConnector have several critical vulnerabilities.
E.g.
golang.org/x/net
Bundled version: 0.0.0-20201021035429-f5854403a974
Requited fix: 0.17.0
Contributor guide
Research direction
Locate the JiraEdgeConnector and the bundled golang.org/x/net dependency, then inspect how its current version is recorded and used. Compare the bundled 0.0.0-20201021035429-f5854403a974 version with the requested 0.17.0 and identify the other critical vulnerabilities mentioned by the issue. Done means the connector no longer bundles the vulnerable versions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100