-
Hi Team,
on running the command:
docker run --rm ossillate/packj audit -p pypi:requests
I get the following error.
"Failed to dump json content to file /tmp/packj_audit_4414d88z/report_zw4uc_a…
-
Key Points for Summary:
- Cloud-Native Security: Cloud-native applications bring new security challenges like securing microservices, containers, and API communications.
- Zero-Trust Architec…
-
https://github.com/lackdaz/saddle/blob/fbc58a1efa37a2f4ce4c2b6588596c21feaf650a/saddle.sh#L17
A specific commit should probably be referenced and signature(s) of pishrink itself checked.
-
**Is your feature request related to a problem? Please describe.**
This feature request proposes to evaluate and (selectively) adopt secure software development best practices recommended by the Open…
gkunz updated
1 month ago
-
### What happended?
In file: [SExpression.java](https://github.com/bcgit/bc-java/blob/1.78.1/pg/src/main/java/org/bouncycastle/gpg/SExpression.java#L147), there is a potential case of null pointer …
-
https://github.com/JacksonQu/Software-Supply-Chain-Security-Assignment1/blob/d446488fdbda84f8264478efa141aa9ba9dba792/main.py#L8C1-L17C9
It would be better if the code is able to handle failed requ…
-
## Vulnerabilities found for metadata-writer:2.3.0
```
For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your pro…
-
I've noticed that this project currently does not generate a Software Bill of Materials (SBOM). An SBOM is a critical document for tracking software dependencies, ensuring compliance, and enhancing se…
-
### Type
Suggestions for Improvement
### What would you like to report?
**Context**
One of the parts of the supply chain in modern ML systems is MLOps software - like i.e. MLFlow, Prefect et…
mik0w updated
6 months ago
-
## Vulnerabilities found for jupyter-web-app:1.9.0
```
For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your pro…