Skip to content

Checkmarx Bot - Auto Pull Request in branch "main" - #3

Open
cx-lucas-ferreira wants to merge 1 commit into
mainfrom
checkmarx-main-LrZi4OEBcBXkHMaN
Open

Checkmarx Bot - Auto Pull Request in branch "main"#3
cx-lucas-ferreira wants to merge 1 commit into
mainfrom
checkmarx-main-LrZi4OEBcBXkHMaN

Conversation

@cx-lucas-ferreira

Copy link
Copy Markdown

Checkmarx created this PR to replace vulnerable packages.
You can check the package details in the Files Changed tab

@cx-lucas-ferreira

cx-lucas-ferreira commented Jul 17, 2026

Copy link
Copy Markdown
Author

Logo
Checkmarx One – Scan Summary & Details878988ce-6966-4d75-810b-3078e3ff4fa5


New Issues (8)

High: 1 · Medium: 1 · Low: 6

Checkmarx found the following issues in this Pull Request

#SeverityIssueSource File / PackageCheckmarx Insight
1HIGHMissing User InstructionDockerfile: 1
detailsAlways set a user in the runtime stage of your Dockerfile. Without it, the container defaults to root, even if earlier build stages define a user.
2MEDIUMApt Get Install Pin Version Not DefinedDockerfile: 7
detailsWhen installing a package, its pin version should be defined
3LOWHealthcheck Instruction MissingDockerfile: 1
detailsEnsure that HEALTHCHECK is being used. The HEALTHCHECK instruction tells Docker how to test a container to check that it is still working
4LOWRun Using aptDockerfile: 7
detailsapt is discouraged by the linux distributions as an unattended tool as its interface may suffer changes between versions. Better use the more stab...
5LOWUnpinned Actions Full Length Commit SHA/push-ecr.yaml: 16
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
6LOWUnpinned Actions Full Length Commit SHA/the-essentials.yml: 90
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
7LOWUnpinned Actions Full Length Commit SHA/push-ecr.yaml: 24
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
8LOWUnpinned Actions Full Length Commit SHA/the-essentials.yml: 114
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...

Fixed Issues (60)

Critical: 5 · High: 33 · Medium: 20 · Low: 2

Great job! The following issues were fixed in this Pull Request

SeverityIssueSource File / Package
CRITICALCVE-2023-37920Python-certifi-2022.9.14
CRITICALCVE-2024-53908Python-Django-4.2.13
CRITICALCVE-2025-59681Python-Django-4.2.13
CRITICALCVE-2025-64459Python-Django-4.2.13
CRITICALCVE-2026-4277Python-Django-4.2.13
HIGHCVE-2021-21240Python-httplib2-0.17.4
HIGHCVE-2022-23472Python-passeo-1.0.4
HIGHCVE-2022-23491Python-certifi-2022.9.14
HIGHCVE-2023-30608Python-sqlparse-0.4.2
HIGHCVE-2023-38325Python-cryptography-35.0.0
HIGHCVE-2023-49083Python-cryptography-35.0.0
HIGHCVE-2023-50782Python-cryptography-35.0.0
HIGHCVE-2024-23342Python-ecdsa-0.18.0b1
HIGHCVE-2024-38875Python-Django-4.2.13
HIGHCVE-2024-39330Python-Django-4.2.13
HIGHCVE-2024-39614Python-Django-4.2.13
HIGHCVE-2024-39689Python-certifi-2022.9.14
HIGHCVE-2024-41989Python-Django-4.2.13
HIGHCVE-2024-41990Python-Django-4.2.13
HIGHCVE-2024-41991Python-Django-4.2.13
HIGHCVE-2024-42005Python-Django-4.2.13
HIGHCVE-2024-4340Python-sqlparse-0.4.2
HIGHCVE-2024-45230Python-Django-4.2.13
HIGHCVE-2024-53907Python-Django-4.2.13
HIGHCVE-2024-56374Python-Django-4.2.13
HIGHCVE-2025-14550Python-Django-4.2.13
HIGHCVE-2025-26699Python-Django-4.2.13
HIGHCVE-2025-57833Python-Django-4.2.13
HIGHCVE-2025-64458Python-Django-4.2.13
HIGHCVE-2025-64460Python-Django-4.2.13
HIGHCVE-2026-1285Python-Django-4.2.13
HIGHCVE-2026-25673Python-Django-4.2.13
HIGHCVE-2026-26007Python-cryptography-35.0.0
HIGHCVE-2026-33034Python-Django-4.2.13
HIGHCVE-2026-3902Python-Django-4.2.13
HIGHCVE-2026-59939Python-httplib2-0.17.4
HIGHCx89a94f30-7a24Python-sqlparse-0.4.2
HIGHCxde995bcc-bbd5Python-cryptography-35.0.0
MEDIUMCVE-2020-11078Python-httplib2-0.17.4
MEDIUMCVE-2023-23931Python-cryptography-35.0.0
MEDIUMCVE-2023-32681Python-requests-2.30.0
MEDIUMCVE-2024-35195Python-requests-2.30.0
MEDIUMCVE-2024-39329Python-Django-4.2.13
MEDIUMCVE-2024-45231Python-Django-4.2.13
MEDIUMCVE-2024-47081Python-requests-2.30.0
MEDIUMCVE-2025-13372Python-Django-4.2.13
MEDIUMCVE-2025-13473Python-Django-4.2.13
MEDIUMCVE-2025-32873Python-Django-4.2.13
MEDIUMCVE-2025-48432Python-Django-4.2.13
MEDIUMCVE-2025-59682Python-Django-4.2.13
MEDIUMCVE-2025-68146Python-filelock-3.14.0
MEDIUMCVE-2026-1207Python-Django-4.2.13
MEDIUMCVE-2026-1287Python-Django-4.2.13
MEDIUMCVE-2026-1312Python-Django-4.2.13
MEDIUMCVE-2026-22701Python-filelock-3.14.0
MEDIUMCVE-2026-25645Python-requests-2.30.0
MEDIUMCVE-2026-33936Python-ecdsa-0.18.0b1
MEDIUMCx126feec9-ba34Python-sqlparse-0.4.2
LOWCVE-2026-25674Python-Django-4.2.13
LOWCVE-2026-34073Python-cryptography-35.0.0

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@cx-lucas-ferreira