actions / upload-artifact

MIT License
3k stars 683 forks source link

Getting Dependabot Alert #574

Open manoj27730 opened 4 weeks ago

manoj27730 commented 4 weeks ago

What happened?

Hi Team,

I am trying to add the actions "https://github.com/actions/upload-artifact" with version v4.3.3 in our Enterprise GitHub repository.

While adding the GitHub Team found, there were 3 vulnerabilities found in the action that you requested for by Dependabot:

The team is unable to import this action for usage in because of the vulnerabilities found in the dependencies used by this action that might pose a security threat.

I have attached the screenshot of the vulnerabilities.

Dependabot_alert

What did you expect to happen?

Fix the Dependabot Alerts

How can we reproduce it?

It's our internal repo.

Anything else we need to know?

No response

What version of the action are you using?

v4.3.3

What are your runner environments?

window

Are you on GitHub Enterprise Server? If so, what version?

No response

manoj27730 commented 3 weeks ago

Hi Team,

Any update on the above issue?

Thanks, Manoj Kumar Sahu

manoj27730 commented 2 days ago

Hi Team,

Any update on the above issue?

Thanks, Manoj Kumar Sahu