Skip to content

πŸ”’ [IBM OSPO Security Notification] β€” IBM/cloud-enterprise-examplesΒ #30

Description

@security-ops-bot

πŸ”’ [IBM OSPO Security Notification] β€” IBM/cloud-enterprise-examples

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β€”
they will never trigger warnings or archiving.

πŸ’‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β†’ Advanced Security β†’ Dependabot security updates β†’ Enable.

Attention: @timroster

Dependabot Alerts

Severity CVE/GHSA Package Affected Patched Deadline Fix PR
πŸ”΄ critical CVE-2026-53486 decompress <= 4.2.1 β€” 2026-09-28 β€”
πŸ”΄ critical CVE-2026-54466 websocket-driver < 0.7.5 0.7.5 2026-09-23 β€”
πŸ”΄ critical CVE-2026-59873 tar <= 7.5.18 7.5.19 2026-09-23 β€”
🟠 high CVE-2026-13149 brace-expansion < 1.1.16 1.1.16 2026-10-16 β€”
🟠 high CVE-2026-73650 svgo >= 1.0.0, < 2.8.3 2.8.3 2026-10-16 β€”
🟠 high CVE-2026-59874 tar <= 7.5.17 7.5.18 2026-10-16 β€”
🟠 high CVE-2026-13311 shell-quote <= 1.8.4 1.9.0 2026-10-16 β€”
🟠 high GHSA-f88m-g3jw-g9cj sharp < 0.35.0 0.35.0 2026-10-16 β€”
🟠 high CVE-2026-59869 js-yaml >= 3.0.0, < 3.15.0 3.15.0 2026-10-16 β€”
🟠 high CVE-2026-73566 tar <= 7.5.20 7.5.21 2026-10-16 β€”
🟠 high CVE-2026-45623 postcss <= 8.5.11 8.5.12 2026-10-16 β€”
🟠 high CVE-2026-73646 postcss <= 8.5.17 8.5.18 2026-10-17 β€”
🟠 high CVE-2026-69185 socket.io-parser >= 3.4.0, < 3.4.5 3.4.5 2026-10-17 β€”
🟠 high CVE-2026-69152 brace-expansion < 1.1.18 1.1.18 2026-10-17 β€”
🟠 high CVE-2026-14257 brace-expansion < 1.1.17 1.1.17 2026-10-17 β€”
🟠 high GHSA-5p4m-2wfm-xmqj js-yaml >= 3.0.0, < 3.15.1 3.15.1 2026-10-16 β€”
🟠 high CVE-2026-59880 immutable < 3.8.4 3.8.4 2026-10-10 β€”
🟠 high CVE-2026-73089 browserslist <= 4.28.6 4.28.7 2026-10-10 β€”
🟠 high CVE-2026-73088 browserslist <= 4.28.6 4.28.7 2026-10-10 β€”
🟠 high CVE-2026-84370 svgo >= 1.0.0, < 2.8.4 2.8.4 2026-10-10 β€”
🟠 high GHSA-rgj7-g3m4-5g8c sharp < 0.35.4 0.35.4 2026-10-10 β€”
🟠 high CVE-2026-84375 js-yaml >= 3.0.0, < 3.15.2 3.15.2 2026-10-13 β€”
🟠 high CVE-2026-59879 immutable < 3.8.4 3.8.4 2026-10-16 β€”
🟑 medium CVE-2026-53550 js-yaml < 3.15.0 3.15.0 2026-12-20 β€”
🟑 medium CVE-2026-54490 websocket-driver < 0.7.5 0.7.5 2026-12-15 β€”
🟑 medium CVE-2026-14620 webpack-dev-server <= 5.2.5 5.2.6 2026-12-15 β€”
🟑 medium CVE-2026-14631 webpack-dev-server <= 5.2.5 5.2.6 2026-12-15 β€”
🟑 medium CVE-2026-59875 tar <= 7.5.16 7.5.17 2026-12-15 β€”
🟑 medium CVE-2026-59871 tar <= 7.5.17 7.5.18 2026-12-15 β€”
🟑 medium CVE-2026-67316 axios < 0.33.0 0.33.0 2026-12-15 β€”
🟑 medium CVE-2026-67319 axios >= 0.8.0, < 0.33.0 0.33.0 2026-12-15 β€”
🟑 medium CVE-2026-10732 decompress <= 4.2.1 β€” 2026-12-16 β€”
🟑 medium CVE-2026-69153 postcss <= 8.5.22 8.5.23 2026-12-16 β€”
🟑 medium CVE-2026-39243 decompress <= 4.2.1 β€” 2026-12-15 β€”
🟑 medium CVE-2026-45822 decode-uri-component <= 0.4.2 0.5.0 2026-12-15 β€”
🟑 medium CVE-2026-82417 qs >= 2.2.5, < 6.16.0 6.16.0 2026-12-09 β€”
🟑 medium CVE-2026-84369 svgo >= 1.0.0, < 2.8.4 2.8.4 2026-12-09 β€”
πŸ”΅ low CVE-2026-12590 body-parser < 1.20.6 1.20.6 β€” β€”

Code Scanning Alerts

Severity Rule Tool Deadline
🟠 high py/clear-text-logging-sensitive-data CodeQL 2026-10-09
🟠 high py/clear-text-logging-sensitive-data CodeQL 2026-10-09
🟠 high py/clear-text-logging-sensitive-data CodeQL 2026-10-09

Secret Scanning Alerts

No open secret scanning alerts.


Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions