-
Posted by Apple Product Security via Fulldisclosure on Oct 31
APPLE-SA-10-29-2024-1 Safari 18.1
Safari 18.1 addresses the following issues.
Information about the security content is also availabl…
-
One regular source of support questions is "why is `some/library:1.2.3` included in the `roave/security-advisories` `conflicts` section?"
This is becoming regular and quite frustrating:
* https…
-
Currently `nuxt-ssr-cache` is has a dependence of `redis` of v2.8.0.
This is triggering a Security advisory npmjs - https://npmjs.com/advisories/1662
When will this module support `redis` v3.1.1…
-
There's a reported "high severity" security issue with System.Text.Json 8.0.4
https://github.com/advisories/GHSA-8g4q-xg66-9fp4
-
setuptools vulnerable to Command Injection via package URL
High severity
setuptools
CVE-2024-6345
SkynetResearchProject/electrum-skynet
contrib/deterministic-build/requirements-bi…
-
## Issue description
This is what someone get's when googling for security advisories for debian vs nixos
### debian.org
![image](https://user-images.githubusercontent.com/127353/61561518-8a2…
-
## Overview
Our security vuln management process is quite manual: Create an issue in github.com/silverstripe-security, create private forks, review pull requests on those forks, merge into a releas…
-
#### Problem
The `WorkflowInstanceHub` currently accepts anonymous requests, which poses a security risk by allowing unrestricted access to SignalR endpoints. To improve security, we need to enforce …
-
chrono - 0.4.19 - segfault in localtime_r - no safe upgrade
time - 0.1.44 - segfault in time crate - upgrade to >=0.2.23
w…
-
Issue edited (original content below)
### What happened?
Our GH dependabot seem to be unable to open PRs to fix vulnerable dependencies:
https://github.com/kumahq/kuma-website/security/dependa…