Update #39
Update #39
153 new alerts including 3 critical severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 3 critical
- 34 high
- 116 medium
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check warning on line 18 in .github/workflows/add_bugs_to_project.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 17 in .github/workflows/check_property_files.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 32 in .github/workflows/check_property_files.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 95 in .github/workflows/container_app_pr.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 81 in .github/workflows/container_app_push.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 158 in .github/workflows/container_app_push.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 44 in .github/workflows/deploy_beta_testing.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 90 in .github/workflows/deploy_beta_testing.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 37 in .github/workflows/generate_war_file.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 27 in .github/workflows/guides_build_sphinx.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 83 in .github/workflows/maven_unit_test.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 133 in .github/workflows/maven_unit_test.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 172 in .github/workflows/maven_unit_test.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 20 in .github/workflows/pr_comment_commands.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 20 in .github/workflows/reviewdog_checkstyle.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 27 in .github/workflows/shellspec.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 44 in .github/workflows/shellspec.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 54 in .github/workflows/shellspec.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 34 in .github/workflows/spi_release.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 60 in .github/workflows/spi_release.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check warning on line 94 in .github/workflows/spi_release.yml
Code scanning / CodeQL
Workflow does not contain permissions Medium
Check failure on line 63 in src/main/webapp/dataverse_header.xhtml
Code scanning / CodeQL
DOM text reinterpreted as HTML High
Check failure on line 676 in src/main/java/edu/harvard/iq/dataverse/api/Datasets.java
Code scanning / CodeQL
Cross-site scripting High
Check failure on line 244 in src/main/java/edu/harvard/iq/dataverse/api/DatasetFieldServiceApi.java
Code scanning / CodeQL
Uncontrolled data used in path expression High
Code scanning / CodeQL
Query built from user-controlled sources High