yup #89
yup #89
11 new alerts including 11 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 11 high
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check failure on line 60 in Android/LuaViewSDK/pom.xml
Code scanning / CodeQL
Failure to use HTTPS or SFTP URL in Maven artifact upload/download High
Check failure on line 64 in Android/LuaViewSDK/pom.xml
Code scanning / CodeQL
Failure to use HTTPS or SFTP URL in Maven artifact upload/download High
Code scanning / CodeQL
Arbitrary file access during archive extraction ("Zip Slip") High
Code scanning / CodeQL
Uncontrolled data used in path expression High
Code scanning / CodeQL
Uncontrolled data used in path expression High
Check failure on line 77 in Android/LuaViewSDK/src/com/taobao/luaview/util/DecryptUtil.java
Code scanning / CodeQL
Use of a broken or risky cryptographic algorithm High
Check failure on line 79 in Android/LuaViewSDK/src/com/taobao/luaview/util/DecryptUtil.java
Code scanning / CodeQL
Use of a broken or risky cryptographic algorithm High
Check failure on line 80 in Android/LuaViewSDK/src/com/taobao/luaview/util/DecryptUtil.java
Code scanning / CodeQL
Using a static initialization vector for encryption High
Check failure on line 480 in Android/LuaViewSDK/src/org/luaj/vm2/Globals.java
Code scanning / CodeQL
Implicit narrowing conversion in compound assignment High
Check failure on line 464 in Android/LuaViewSDK/src/org/luaj/vm2/compiler/FuncState.java
Code scanning / CodeQL
Implicit narrowing conversion in compound assignment High
Check failure on line 20 in Android/LuaViewSDK/target/AndroidManifest.xml
Code scanning / CodeQL
Android debuggable attribute enabled High