-
Notifications
You must be signed in to change notification settings - Fork 10
π Security Alerts β IBM/vpc-java-sdk #83
Description
π Security Alerts β IBM/vpc-java-sdk
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: @edabe @astha-jain @ibm-vpc @sumitkumartiwari @deepakibms
Dependabot Alerts
| Severity | CVE/GHSA | Package | Affected | Patched | Fix PR |
|---|---|---|---|---|---|
| π‘ medium | CVE-2026-48758 | @sigstore/core | <= 3.2.0 | 3.2.1 | β |
| π‘ medium | CVE-2026-53550 | js-yaml | >= 4.0.0, <= 4.1.1 | 4.2.0 | β |
| π high | CVE-2026-48815 | sigstore | <= 4.1.0 | 4.1.1 | β |
| π‘ medium | CVE-2026-59871 | tar | <= 7.5.17 | 7.5.18 | β |
| π high | CVE-2026-59869 | js-yaml | >= 4.0.0, < 4.3.0 | 4.3.0 | β |
| π high | CVE-2026-13149 | brace-expansion | >= 2.0.0, < 2.1.2 | 2.1.2 | β |
| π high | CVE-2026-69192 | ip-address | <= 10.3.0 | 10.3.1 | β |
| π high | GHSA-5p4m-2wfm-xmqj | js-yaml | >= 4.0.0, < 4.3.1 | 4.3.1 | β |
| π΅ low | CVE-2026-9358 | postcss-selector-parser | >= 7.1.0, < 7.1.3 | 7.1.3 | β |
| π high | CVE-2026-84375 | js-yaml | >= 4.0.0, < 4.3.2 | 4.3.2 | β |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.