Skip to content

Conversation

github-actions[bot]
Copy link
Contributor

Automated changes by create-pull-request GitHub action

@github-actions github-actions bot added documentation Improvements or additions to documentation polaris python labels Sep 29, 2024
@github-actions github-actions bot force-pushed the create-pull-request/patch branch from 1e4f8f7 to 06d1850 Compare November 29, 2024 17:14
@github-actions github-actions bot force-pushed the create-pull-request/patch branch from 06d1850 to cda06e6 Compare September 23, 2025 10:23
@github-actions github-actions bot force-pushed the create-pull-request/patch branch from cda06e6 to 165a61a Compare September 23, 2025 10:38
Copy link

endorlabs bot commented Sep 23, 2025

Warning

Endor Labs detected 1 policy violations associated with this pull request.

Please review the findings that caused the policy violations.

📋 Policy: SCA - PR RubrikInc (1 finding)

📥 Package pypi://sample/pcr-azure@pr/130

⤵️ Dependency: pypi://[email protected]
🚩 GHSA-47xc-9rr2-q7p4: Improper Control of Generation of Code ('Code Injection') in Azure CLI

Details

  • Severity: Critical
  • Tags: Direct Normal Potentially Reachable Function Potentially Reachable Dependency Fix Available Warning
  • Categories: Security Vulnerability SCA
  • Remediation: Update sample/pcr-azure@pr/130 to use azure-cli version 2.40.0 (current: 2.39.0, latest: 2.77.0).

This comment was automatically generated by Endor Labs.
Scanned @ 09-23-2025 10:41:38 UTC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation polaris python
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant