Skip to content

Conversation

@bbossola
Copy link

@bbossola bbossola commented Mar 6, 2018

Dear development team @QuBiT,

My name is Bruno and as part of ongoing projects at meterian.io, we regularly scan open source projects on GitHub, BitBucket and other repositories in order to warn developers about vulnerabilities in their included libraries, which may negatively affect their products.

Analysing your project we detected it may be exposed to these publicly disclosed vulnerabilities:

You can read our assessment report here, it includes also some suggestion regarding obsolete libraries that appear still to be used in your project.

We kindly recommend you accept this PR as a starting point in order to resolve this problem, although this is still an incomplete solution, as in order to fully resolve the issue you will need also a major upgrade of at least one library. Please note (and excuse my shameless plug!) we distribute a client solution that can be easily integrated into your build pipeline to protect both open and closed source projects. We are able to find vulnerabilities, suggest library upgrades and (soon) detect license violations.

Please do not hesitate to contact us: we are currently running a pilot and we will be glad to have you on board!

bruno@meterian.io

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant