javadiscord / java-discord-api

A wrapper over the discord API to create bots using Java
GNU General Public License v3.0
7 stars 8 forks source link

Recommendation: Free Open Source GitHub Security Engineer plugin - Pixeebot assists Hardening Code, Fixing Bugs & addressing Sonar Issues #129

Closed pixeeai closed 1 month ago

pixeeai commented 1 month ago

Meet your automated product security engineer Pixeebot fixes vulnerabilities, hardens code, squashes bugs, and gives engineers more time to focus on the work that counts.

More Details: https://github.com/apps/pixeebot

pixeeai commented 1 month ago

I just forked your repo & this was the first recommendation pr the bot came up with:

Introduced protections against "zip slip" attacks

surajkumar commented 1 month ago

@pixeebot next

surajkumar commented 1 month ago

Fixed

pixeeai commented 1 month ago

@pixeebot next

pixeeai commented 1 month ago

@surajkumar were you able to get it installed successfully on your repository?

surajkumar commented 1 month ago

Yeah, thanks for raising the issue. It's not a good idea for me to include your dependency into my repository for a very small fix so we coded that ourselves.

This was an issue that Sonar had already raised with suggested fixes prior to Pixeeai hence why.

pixeeai commented 1 month ago

@surajkumar No worries. We also recommend many changes that don't include dependency additions. Were you able to try to get it installed via the GitHub Marketplace?

Here is the link: https://github.com/apps/pixeebot