💾 IT Security Tools 🕛 vor 2 Monaten 3 Min Lesezeit SECURITY-FEED
0

v0.384.0

↗ Quelle (GitHub · github.com)
🗣️ Stimme:
📑 Inhaltsübersicht
🐙
$ git clone https://github.com/dependabot/dependabot-core.git

What's Changed



  • Bazel: Fix prerelease filtering with same-release-line scoping by

  • Respect cooldown for Docker digest updates and suppress multi-arch no-ops by

  • Bypass npmrc min-release-age for transitive npm security updates by

  • Ratchet the Sorbet T.untyped burndown by

  • feat(docker): implement single-platform image detection and optimize manifest fetching logic by

  • Fix private registry config not found error not being raised issue in npm_and_yarn by

  • don't fail if nuget cred is missing url by

  • Type commit_message_options with a value object by

  • Type the Dependabot config file parser by

  • Fix Terraform registry replacement typing and credential semantics by

  • fix: avoid path collisions for SHA-pinned GitHub Actions by

  • Nix: skip flake inputs pinned to a bare commit SHA by

  • Type the vulnerability version-range renderer by

  • Add JobCommand enum and Command property to NuGet Job model by

  • Upgrade Ruby to 4.0.5 by

  • Bump updater-core image to RubyGems/Bundler 4.0.13 by

  • Fix issue with PrivateRegistryConfigNotFound error incorrectly firing when scope is configured by

  • Fake MSBuild SolutionDir during NuGet discovery ( in in in in in in in in with @Copilot in in in in in in in in


New Contributors






Full Changelog: v0.383.0...v0.384.0

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf github.com.
↗ Original-Artikel auf github.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
6 Quellen
CVE-2022-44255 | TOTOLINK LR350 9.3.5u.6369_B20220309 buffer overflow (EUVD-2022-47204)
2 Quellen
CVE-2026-68426 | Linux Kernel up to 6.18.41/7.1.5/7.2-rc3 xfrm validate_xmit_skb_list use after free (Nessus ID 346426)
1 Quelle
Windows 11 Probleme mit gültiger Domänenanmeldung nach September-Update [Workaround]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten v0.384.0

Thematisch verwandte Begriffe: v03840 · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...