karths/binary_classification_train_process
015
1Unnamed: 0,id,type,created_at,repo,repo_url,action,title,labels,body,index,text_combine,label,text,binary_label212556,14978450300.0,IssuesEvent,2021-01-28 10:50:54,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,User details page > Search bar is missing,Bug P2 Participant manager Process: Fixed Process: Release 2 Process: Tested QA Process: Tested dev UI,"AR : Search bar is missing
3ER : Search bar should be present as per invision
4
5",4.0,"User details page > Search bar is missing - AR : Search bar is missing
6ER : Search bar should be present as per invision
7
8",1,user details page search bar is missing ar search bar is missing er search bar should be present as per invision ,19285499,8761407515.0,IssuesEvent,2018-12-16 17:04:41,RobotLocomotion/drake,https://api.github.com/repos/RobotLocomotion/drake,opened,shared_library: Different behavior with subnormal numbers between static and shared linking,priority: medium team: kitware,"Relates #10244 - the solution there is to avoid using subnormal numbers, but I still want to understand why we have a difference in computations due to linking modality.
10
11From that discussion:
12> [...] it's because something in GetNextSampleTime has markedly different between static linking and shared library linking:
13> EricCousineau-TRI@f2027d6#diff-dfc5081278527b906fd0f3245d73dfd4R23
14
15\cc @edrumwri @sherm1 ",1.0,"shared_library: Different behavior with subnormal numbers between static and shared linking - Relates #10244 - the solution there is to avoid using subnormal numbers, but I still want to understand why we have a difference in computations due to linking modality.
16
17From that discussion:
18> [...] it's because something in GetNextSampleTime has markedly different between static linking and shared library linking:
19> EricCousineau-TRI@f2027d6#diff-dfc5081278527b906fd0f3245d73dfd4R23
20
21\cc @edrumwri @sherm1 ",0,shared library different behavior with subnormal numbers between static and shared linking relates the solution there is to avoid using subnormal numbers but i still want to understand why we have a difference in computations due to linking modality from that discussion it s because something in getnextsampletime has markedly different between static linking and shared library linking ericcousineau tri diff cc edrumwri ,0227939,8125087465.0,IssuesEvent,2018-08-16 19:44:14,MicrosoftDocs/azure-docs,https://api.github.com/repos/MicrosoftDocs/azure-docs,closed,AMQP .NET: Broken Anchor Link,service-bus-messaging/svc,"Priority: Minor
23Type: Broken Link
24
25Looks like https://github.com/MicrosoftDocs/azure-docs/commit/ed466dcd1b4f3a690d08f04288cb48f98ac37003 is what changed the header, so change line 28 from:
26
27```
28In the current release, there are a few API features that are not supported when using AMQP. These unsupported features are listed later in the section [Unsupported features, restrictions, and behavioral differences](#unsupported-features-restrictions-and-behavioral-differences). Some of the advanced configuration settings also have a different meaning when using AMQP.
29```
30
31to
32
33```
34In the current release, there are a few API features that are not supported when using AMQP. These unsupported features are listed later in the section [Unsupported features, restrictions, and behavioral differences](#behavioral-differences). Some of the advanced configuration settings also have a different meaning when using AMQP.
35```
36
37Potentially reword as well since the heading no longer has ""unsupported features"" in it.
38
39---
40#### Document Details
41
42⚠ *Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.*
43
44* ID: e28d060c-a765-ed3a-9de5-7ba9ca93d649
45* Version Independent ID: e6e933ef-50d7-712e-fb4b-e7ef555fb1b6
46* Content: [Azure Service Bus with .NET and AMQP 1.0](https://docs.microsoft.com/en-us/azure/service-bus-messaging/service-bus-amqp-dotnet#unsupported-features-restrictions-and-behavioral-differences)
47* Content Source: [articles/service-bus-messaging/service-bus-amqp-dotnet.md](https://github.com/Microsoft/azure-docs/blob/master/articles/service-bus-messaging/service-bus-amqp-dotnet.md)
48* Service: **service-bus-messaging**
49* GitHub Login: @sethmanheim
50* Microsoft Alias: **sethm**",1.0,"AMQP .NET: Broken Anchor Link - Priority: Minor
51Type: Broken Link
52
53Looks like https://github.com/MicrosoftDocs/azure-docs/commit/ed466dcd1b4f3a690d08f04288cb48f98ac37003 is what changed the header, so change line 28 from:
54
55```
56In the current release, there are a few API features that are not supported when using AMQP. These unsupported features are listed later in the section [Unsupported features, restrictions, and behavioral differences](#unsupported-features-restrictions-and-behavioral-differences). Some of the advanced configuration settings also have a different meaning when using AMQP.
57```
58
59to
60
61```
62In the current release, there are a few API features that are not supported when using AMQP. These unsupported features are listed later in the section [Unsupported features, restrictions, and behavioral differences](#behavioral-differences). Some of the advanced configuration settings also have a different meaning when using AMQP.
63```
64
65Potentially reword as well since the heading no longer has ""unsupported features"" in it.
66
67---
68#### Document Details
69
70⚠ *Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.*
71
72* ID: e28d060c-a765-ed3a-9de5-7ba9ca93d649
73* Version Independent ID: e6e933ef-50d7-712e-fb4b-e7ef555fb1b6
74* Content: [Azure Service Bus with .NET and AMQP 1.0](https://docs.microsoft.com/en-us/azure/service-bus-messaging/service-bus-amqp-dotnet#unsupported-features-restrictions-and-behavioral-differences)
75* Content Source: [articles/service-bus-messaging/service-bus-amqp-dotnet.md](https://github.com/Microsoft/azure-docs/blob/master/articles/service-bus-messaging/service-bus-amqp-dotnet.md)
76* Service: **service-bus-messaging**
77* GitHub Login: @sethmanheim
78* Microsoft Alias: **sethm**",0,amqp net broken anchor link priority minor type broken link looks like is what changed the header so change line from in the current release there are a few api features that are not supported when using amqp these unsupported features are listed later in the section unsupported features restrictions and behavioral differences some of the advanced configuration settings also have a different meaning when using amqp to in the current release there are a few api features that are not supported when using amqp these unsupported features are listed later in the section behavioral differences some of the advanced configuration settings also have a different meaning when using amqp potentially reword as well since the heading no longer has unsupported features in it document details ⚠ do not edit this section it is required for docs microsoft com ➟ github issue linking id version independent id content content source service service bus messaging github login sethmanheim microsoft alias sethm ,0793193,3833126424.0,IssuesEvent,2016-04-01 01:00:36,anholt/linux,https://api.github.com/repos/anholt/linux,closed,vc4: Queue V3D bin/render jobs in parallel,performance,Varad has been working on taking my anholt/vc4-kms-v3d-rpi2-binrendersubmit-2 branch and fixing it. Hopefully done soon.,True,vc4: Queue V3D bin/render jobs in parallel - Varad has been working on taking my anholt/vc4-kms-v3d-rpi2-binrendersubmit-2 branch and fixing it. Hopefully done soon.,0, queue bin render jobs in parallel varad has been working on taking my anholt kms binrendersubmit branch and fixing it hopefully done soon ,080325061,27845629376.0,IssuesEvent,2023-03-20 15:19:47,QubesOS/updates-status,https://api.github.com/repos/QubesOS/updates-status,closed,video-companion v1.0.1-1 (r4.1),r4.1-buster-cur-test r4.1-dom0-cur-test r4.1-bullseye-cur-test r4.1-centos-stream8-cur-test r4.1-bookworm-cur-test r4.1-fc36-cur-test r4.1-fc37-cur-test r4.1-fc38-cur-test,"Update of video-companion to v1.0.1-1 for Qubes r4.1, see comments below for details.81 82Built from: https://github.com/QubesOS/qubes-video-companion/commit/7b568f15cffe8ec0fde5aab37f5afe3d62ce688583 84[Changes since previous version](https://github.com/QubesOS/qubes-video-companion/compare/v2.0.0...v1.0.1-1):85QubesOS/qubes-video-companion@7b568f1 version 1.0.1-186QubesOS/qubes-video-companion@313ce9b pylint: disable consider-using-f-string87QubesOS/qubes-video-companion@038b4f8 tests: webcam test is supposed to work now88QubesOS/qubes-video-companion@ce725b8 webcam: workaround gstreamer bug for video/x-raw source89QubesOS/qubes-video-companion@741a487 Drop --buffer-size=0, it doesn't do anything90QubesOS/qubes-video-companion@dd8e6be tests: log more details on failure91QubesOS/qubes-video-companion@9bb6481 sender/webcam: support raw source stream too92QubesOS/qubes-video-companion@9dafa4e Remove 'colorimetry' pipeline constraint93QubesOS/qubes-video-companion@b3706f8 ci: limit pylint to actual package94QubesOS/qubes-video-companion@cb91413 tests: add skeleton for webcam test too95QubesOS/qubes-video-companion@14b44ce tests: add basic integration test for screen share96QubesOS/qubes-video-companion@f710822 Add v4l-utils dependency97QubesOS/qubes-video-companion@82c1038 Make pylint happy again98QubesOS/qubes-video-companion@683e401 Reformat code according to python-black99QubesOS/qubes-video-companion@240c140 Make pylint happy100QubesOS/qubes-video-companion@7800118 Add .pylintrc from core-admin and fix deps101QubesOS/qubes-video-companion@58cf260 Make shellcheck happy102QubesOS/qubes-video-companion@a790ea9 Qubes Builder integration103QubesOS/qubes-video-companion@51f9c35 Rework .gitlab-ci.yml104QubesOS/qubes-video-companion@c7215ba Allow @default in the qrexec policies105QubesOS/qubes-video-companion@e67ad19 Use @default as the destination if none is passed106QubesOS/qubes-video-companion@4939934 Fix debian/rules107QubesOS/qubes-video-companion@418a7c1 Convert icon.png108QubesOS/qubes-video-companion@695043a Make install a bit more robust109QubesOS/qubes-video-companion@3c7d3cd Check for /etc/qubes-release in dom0110QubesOS/qubes-video-companion@7af0651 Avoid overbroad except111QubesOS/qubes-video-companion@302352f Minor Python improvements112QubesOS/qubes-video-companion@0b8b901 Add basic comments to the qrexec policies113QubesOS/qubes-video-companion@fb6db6f Don't hardcode dom0 as a destination114QubesOS/qubes-video-companion@ca39b24 Avoid tripping -o pipefail115QubesOS/qubes-video-companion@43343bc Improve documentation116QubesOS/qubes-video-companion@ae28a82 Merge branch 'packaging-improvements' from DemiMarie117QubesOS/qubes-video-companion@72cd1c6 Small fix ups118QubesOS/qubes-video-companion@d7804d3 Improved packaging script119QubesOS/qubes-video-companion@ed259e9 Split the RPM package into separate packages120QubesOS/qubes-video-companion@ce98c5d Mark various targets as .PHONY121QubesOS/qubes-video-companion@e81f522 Avoid installing v4l2loopback scripts by default122 123Referenced issues:124 125 126If you're release manager, you can issue GPG-inline signed command:127 128* `Upload video-companion 7b568f15cffe8ec0fde5aab37f5afe3d62ce6885 r4.1 current repo` (available 7 days from now)129* `Upload video-companion 7b568f15cffe8ec0fde5aab37f5afe3d62ce6885 r4.1 current (dists) repo`, you can choose subset of distributions, like `vm-fc24 vm-fc25` (available 7 days from now)130* `Upload video-companion 7b568f15cffe8ec0fde5aab37f5afe3d62ce6885 r4.1 security-testing repo`131 132Above commands will work only if packages in current-testing repository were built from given commit (i.e. no new version superseded it).133",8.0,"video-companion v1.0.1-1 (r4.1) - Update of video-companion to v1.0.1-1 for Qubes r4.1, see comments below for details.134 135Built from: https://github.com/QubesOS/qubes-video-companion/commit/7b568f15cffe8ec0fde5aab37f5afe3d62ce6885136 137[Changes since previous version](https://github.com/QubesOS/qubes-video-companion/compare/v2.0.0...v1.0.1-1):138QubesOS/qubes-video-companion@7b568f1 version 1.0.1-1139QubesOS/qubes-video-companion@313ce9b pylint: disable consider-using-f-string140QubesOS/qubes-video-companion@038b4f8 tests: webcam test is supposed to work now141QubesOS/qubes-video-companion@ce725b8 webcam: workaround gstreamer bug for video/x-raw source142QubesOS/qubes-video-companion@741a487 Drop --buffer-size=0, it doesn't do anything143QubesOS/qubes-video-companion@dd8e6be tests: log more details on failure144QubesOS/qubes-video-companion@9bb6481 sender/webcam: support raw source stream too145QubesOS/qubes-video-companion@9dafa4e Remove 'colorimetry' pipeline constraint146QubesOS/qubes-video-companion@b3706f8 ci: limit pylint to actual package147QubesOS/qubes-video-companion@cb91413 tests: add skeleton for webcam test too148QubesOS/qubes-video-companion@14b44ce tests: add basic integration test for screen share149QubesOS/qubes-video-companion@f710822 Add v4l-utils dependency150QubesOS/qubes-video-companion@82c1038 Make pylint happy again151QubesOS/qubes-video-companion@683e401 Reformat code according to python-black152QubesOS/qubes-video-companion@240c140 Make pylint happy153QubesOS/qubes-video-companion@7800118 Add .pylintrc from core-admin and fix deps154QubesOS/qubes-video-companion@58cf260 Make shellcheck happy155QubesOS/qubes-video-companion@a790ea9 Qubes Builder integration156QubesOS/qubes-video-companion@51f9c35 Rework .gitlab-ci.yml157QubesOS/qubes-video-companion@c7215ba Allow @default in the qrexec policies158QubesOS/qubes-video-companion@e67ad19 Use @default as the destination if none is passed159QubesOS/qubes-video-companion@4939934 Fix debian/rules160QubesOS/qubes-video-companion@418a7c1 Convert icon.png161QubesOS/qubes-video-companion@695043a Make install a bit more robust162QubesOS/qubes-video-companion@3c7d3cd Check for /etc/qubes-release in dom0163QubesOS/qubes-video-companion@7af0651 Avoid overbroad except164QubesOS/qubes-video-companion@302352f Minor Python improvements165QubesOS/qubes-video-companion@0b8b901 Add basic comments to the qrexec policies166QubesOS/qubes-video-companion@fb6db6f Don't hardcode dom0 as a destination167QubesOS/qubes-video-companion@ca39b24 Avoid tripping -o pipefail168QubesOS/qubes-video-companion@43343bc Improve documentation169QubesOS/qubes-video-companion@ae28a82 Merge branch 'packaging-improvements' from DemiMarie170QubesOS/qubes-video-companion@72cd1c6 Small fix ups171QubesOS/qubes-video-companion@d7804d3 Improved packaging script172QubesOS/qubes-video-companion@ed259e9 Split the RPM package into separate packages173QubesOS/qubes-video-companion@ce98c5d Mark various targets as .PHONY174QubesOS/qubes-video-companion@e81f522 Avoid installing v4l2loopback scripts by default175 176Referenced issues:177 178 179If you're release manager, you can issue GPG-inline signed command:180 181* `Upload video-companion 7b568f15cffe8ec0fde5aab37f5afe3d62ce6885 r4.1 current repo` (available 7 days from now)182* `Upload video-companion 7b568f15cffe8ec0fde5aab37f5afe3d62ce6885 r4.1 current (dists) repo`, you can choose subset of distributions, like `vm-fc24 vm-fc25` (available 7 days from now)183* `Upload video-companion 7b568f15cffe8ec0fde5aab37f5afe3d62ce6885 r4.1 security-testing repo`184 185Above commands will work only if packages in current-testing repository were built from given commit (i.e. no new version superseded it).186",0,video companion update of video companion to for qubes see comments below for details built from qubesos qubes video companion version qubesos qubes video companion pylint disable consider using f string qubesos qubes video companion tests webcam test is supposed to work now qubesos qubes video companion webcam workaround gstreamer bug for video x raw source qubesos qubes video companion drop buffer size it doesn t do anything qubesos qubes video companion tests log more details on failure qubesos qubes video companion sender webcam support raw source stream too qubesos qubes video companion remove colorimetry pipeline constraint qubesos qubes video companion ci limit pylint to actual package qubesos qubes video companion tests add skeleton for webcam test too qubesos qubes video companion tests add basic integration test for screen share qubesos qubes video companion add utils dependency qubesos qubes video companion make pylint happy again qubesos qubes video companion reformat code according to python black qubesos qubes video companion make pylint happy qubesos qubes video companion add pylintrc from core admin and fix deps qubesos qubes video companion make shellcheck happy qubesos qubes video companion qubes builder integration qubesos qubes video companion rework gitlab ci yml qubesos qubes video companion allow default in the qrexec policies qubesos qubes video companion use default as the destination if none is passed qubesos qubes video companion fix debian rules qubesos qubes video companion convert icon png qubesos qubes video companion make install a bit more robust qubesos qubes video companion check for etc qubes release in qubesos qubes video companion avoid overbroad except qubesos qubes video companion minor python improvements qubesos qubes video companion add basic comments to the qrexec policies qubesos qubes video companion don t hardcode as a destination qubesos qubes video companion avoid tripping o pipefail qubesos qubes video companion improve documentation qubesos qubes video companion merge branch packaging improvements from demimarie qubesos qubes video companion small fix ups qubesos qubes video companion improved packaging script qubesos qubes video companion split the rpm package into separate packages qubesos qubes video companion mark various targets as phony qubesos qubes video companion avoid installing scripts by default referenced issues if you re release manager you can issue gpg inline signed command upload video companion current repo available days from now upload video companion current dists repo you can choose subset of distributions like vm vm available days from now upload video companion security testing repo above commands will work only if packages in current testing repository were built from given commit i e no new version superseded it ,018718677,24594197761.0,IssuesEvent,2022-10-14 06:47:37,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[FHIR] All the created activities in the study builder are not mapping into the FHIR datastore,Bug Blocker P0 Response datastore Process: Fixed Process: Tested dev,"Steps:
1881. Create multiple activities in SB and launch the study [Created around 15 to 20 activities in SB]
1892. Go to the google cloud console
1903. Search for FHIR viewer
1914. Click on the particular dataset and click on the FHIR datastore
1925. Search for the Questionnaire and click on it
1936. Observe
194
195AR: All the activities created in the Study builder are not getting mapped in to the Questionnaire of the FHIR datastore
196ER: All the activities created in the SB should get mapped into FHIR store (As per above scenario only 6 activities are mapped into FHIR store)
197
198",2.0,"[FHIR] All the created activities in the study builder are not mapping into the FHIR datastore - Steps:
1991. Create multiple activities in SB and launch the study [Created around 15 to 20 activities in SB]
2002. Go to the google cloud console
2013. Search for FHIR viewer
2024. Click on the particular dataset and click on the FHIR datastore
2035. Search for the Questionnaire and click on it
2046. Observe
205
206AR: All the activities created in the Study builder are not getting mapped in to the Questionnaire of the FHIR datastore
207ER: All the activities created in the SB should get mapped into FHIR store (As per above scenario only 6 activities are mapped into FHIR store)
208
209",1, all the created activities in the study builder are not mapping into the fhir datastore steps create multiple activities in sb and launch the study go to the google cloud console search for fhir viewer click on the particular dataset and click on the fhir datastore search for the questionnaire and click on it observe ar all the activities created in the study builder are not getting mapped in to the questionnaire of the fhir datastore er all the activities created in the sb should get mapped into fhir store as per above scenario only activities are mapped into fhir store ,121018522,24551878629.0,IssuesEvent,2022-10-12 13:12:56,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[iOS] Review consent should not get displayed for the enrolled users in the following scenario,Bug P0 iOS Process: Fixed Process: Tested QA Process: Tested dev,"Steps:
2111. Create a study in SB and launch the study
2122. Click on edit study
2133. Update the consent and enforce the consent for the enrolled participant
2144. Publish the update
2155. Launch the mobile app and sign up or sign in to the mobile app
2166. Click on the particular study
2177. Enroll to the study
2188. Go back to the study list screen
2199. Again click on the enrolled study
22010. Observe
221
222AR: The review consent popup is getting displayed to the newly enrolled participants in the above scenario
223ER: The review consent popup should not be displayed to the newly enrolled participants in the above scenario
224
225
226
227",3.0,"[iOS] Review consent should not get displayed for the enrolled users in the following scenario - Steps:
2281. Create a study in SB and launch the study
2292. Click on edit study
2303. Update the consent and enforce the consent for the enrolled participant
2314. Publish the update
2325. Launch the mobile app and sign up or sign in to the mobile app
2336. Click on the particular study
2347. Enroll to the study
2358. Go back to the study list screen
2369. Again click on the enrolled study
23710. Observe
238
239AR: The review consent popup is getting displayed to the newly enrolled participants in the above scenario
240ER: The review consent popup should not be displayed to the newly enrolled participants in the above scenario
241
242
243
244",1, review consent should not get displayed for the enrolled users in the following scenario steps create a study in sb and launch the study click on edit study update the consent and enforce the consent for the enrolled participant publish the update launch the mobile app and sign up or sign in to the mobile app click on the particular study enroll to the study go back to the study list screen again click on the enrolled study observe ar the review consent popup is getting displayed to the newly enrolled participants in the above scenario er the review consent popup should not be displayed to the newly enrolled participants in the above scenario ,12453689,6554456761.0,IssuesEvent,2017-09-06 06:01:07,gizmecano/opencart-2-fr,https://api.github.com/repos/gizmecano/opencart-2-fr,closed,Check compatibility with versions released in the 2.0.x series,compatibility,"Check compatibility with versions released in the 2.0.x series:
246
247- [x] [2.0.2.0](https://github.com/opencart/opencart/releases/tag/2.0.2.0)
248 - Rename `default` files (#5)
249 - Add new files in `admin` folder (#6)
250 - Add new files in `catalog` folder (#7)
251 - Revise current files in `admin` folder (#8)
252 - Revise current files in `catalog` folder (#9)
253- [x] [2.0.3.0](https://github.com/opencart/opencart/releases/tag/2.0.3.0)
254 - Add 4 new files in `admin` folder (#12)
255 - Add 1 new file in `catalog` folder (#13)
256 - Revise 8 files in `admin` folder (#14)
257 - Revise 1 file in `catalog` folder (#15)
258- [x] [2.0.3.1](https://github.com/opencart/opencart/releases/tag/2.0.3.1)
259 - Add new file in `catalog` folder (#19)
260 - Revise current file in `admin` folder (#20)",True,"Check compatibility with versions released in the 2.0.x series - Check compatibility with versions released in the 2.0.x series:
261
262- [x] [2.0.2.0](https://github.com/opencart/opencart/releases/tag/2.0.2.0)
263 - Rename `default` files (#5)
264 - Add new files in `admin` folder (#6)
265 - Add new files in `catalog` folder (#7)
266 - Revise current files in `admin` folder (#8)
267 - Revise current files in `catalog` folder (#9)
268- [x] [2.0.3.0](https://github.com/opencart/opencart/releases/tag/2.0.3.0)
269 - Add 4 new files in `admin` folder (#12)
270 - Add 1 new file in `catalog` folder (#13)
271 - Revise 8 files in `admin` folder (#14)
272 - Revise 1 file in `catalog` folder (#15)
273- [x] [2.0.3.1](https://github.com/opencart/opencart/releases/tag/2.0.3.1)
274 - Add new file in `catalog` folder (#19)
275 - Revise current file in `admin` folder (#20)",0,check compatibility with versions released in the x series check compatibility with versions released in the x series rename default files add new files in admin folder add new files in catalog folder revise current files in admin folder revise current files in catalog folder add new files in admin folder add new file in catalog folder revise files in admin folder revise file in catalog folder add new file in catalog folder revise current file in admin folder ,027668265,14918205915.0,IssuesEvent,2021-01-22 21:14:55,tom9carthron1/servicetalk,https://api.github.com/repos/tom9carthron1/servicetalk,opened,CVE-2018-5382 (High) detected in bcprov-jdk15-140.jar,security vulnerability,"## CVE-2018-5382 - High Severity Vulnerability277<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>bcprov-jdk15-140.jar</b></p></summary>278 279<p>The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. The package is organised280 so that it contains a light-weight API suitable for use in any environment (including the newly released J2ME) 281 with the additional infrastructure to conform the algorithms to the JCE framework.</p>282<p>Library home page: <a href=""http://www.bouncycastle.org/java.html"">http://www.bouncycastle.org/java.html</a></p>283<p>Path to dependency file: servicetalk/servicetalk-dns-discovery-netty/build.gradle</p>284<p>Path to vulnerable library: /tmp/ws-ua_20210122205702_PRGYMR/downloadResource_JSCHES/20210122211315/bcprov-jdk15-140.jar</p>285<p>286 287Dependency Hierarchy:288 - apacheds-protocol-dns-1.5.7.jar (Root Library)289 - apacheds-core-jndi-1.5.7.jar290 - apacheds-core-1.5.7.jar291 - :x: **bcprov-jdk15-140.jar** (Vulnerable Library)292<p>Found in HEAD commit: <a href=""https://github.com/tom9carthron1/servicetalk/commit/39fa324cb5853d697835802bdab3ffb89c559bc6"">39fa324cb5853d697835802bdab3ffb89c559bc6</a></p>293<p>Found in base branch: <b>main</b></p>294</p>295</details>296<p></p>297<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> Vulnerability Details</summary>298<p> 299 300Bouncy Castle BKS version 1 keystore (BKS-V1) files use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS-V1 keystore. All BKS-V1 keystores are vulnerable. Bouncy Castle release 1.47 introduces BKS version 2, which uses a 160-bit MAC.301 302<p>Publish Date: 2018-04-16303<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2018-5382>CVE-2018-5382</a></p>304</p>305</details>306<p></p>307<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>9.8</b>)</summary>308<p>309 310Base Score Metrics:311- Exploitability Metrics:312 - Attack Vector: Network313 - Attack Complexity: Low314 - Privileges Required: None315 - User Interaction: None316 - Scope: Unchanged317- Impact Metrics:318 - Confidentiality Impact: High319 - Integrity Impact: High320 - Availability Impact: High321</p>322For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.323</p>324</details>325<p></p>326<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>327<p>328 329<p>Type: Upgrade version</p>330<p>Origin: <a href=""https://vulners.com/cert/VU:306792"">https://vulners.com/cert/VU:306792</a></p>331<p>Release Date: 2018-04-16</p>332<p>Fix Resolution: org.bouncycastle:bcprov-ext-jdk14:1.47,org.bouncycastle:bcprov-ext-jdk15on:1.47,org.bouncycastle:bcprov-jdk14:1.47</p>333 334</p>335</details>336<p></p>337 338<!-- <REMEDIATE>{""isOpenPROnVulnerability"":false,""isPackageBased"":true,""isDefaultBranch"":true,""packages"":[{""packageType"":""Java"",""groupId"":""bouncycastle"",""packageName"":""bcprov-jdk15"",""packageVersion"":""140"",""isTransitiveDependency"":true,""dependencyTree"":""org.apache.directory.server:apacheds-protocol-dns:1.5.7;org.apache.directory.server:apacheds-core-jndi:1.5.7;org.apache.directory.server:apacheds-core:1.5.7;bouncycastle:bcprov-jdk15:140"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""org.bouncycastle:bcprov-ext-jdk14:1.47,org.bouncycastle:bcprov-ext-jdk15on:1.47,org.bouncycastle:bcprov-jdk14:1.47""}],""vulnerabilityIdentifier"":""CVE-2018-5382"",""vulnerabilityDetails"":""Bouncy Castle BKS version 1 keystore (BKS-V1) files use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS-V1 keystore. All BKS-V1 keystores are vulnerable. Bouncy Castle release 1.47 introduces BKS version 2, which uses a 160-bit MAC."",""vulnerabilityUrl"":""https://vuln.whitesourcesoftware.com/vulnerability/CVE-2018-5382"",""cvss3Severity"":""high"",""cvss3Score"":""9.8"",""cvss3Metrics"":{""A"":""High"",""AC"":""Low"",""PR"":""None"",""S"":""Unchanged"",""C"":""High"",""UI"":""None"",""AV"":""Network"",""I"":""High""},""extraData"":{}}</REMEDIATE> -->",True,"CVE-2018-5382 (High) detected in bcprov-jdk15-140.jar - ## CVE-2018-5382 - High Severity Vulnerability339<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>bcprov-jdk15-140.jar</b></p></summary>340 341<p>The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. The package is organised342 so that it contains a light-weight API suitable for use in any environment (including the newly released J2ME) 343 with the additional infrastructure to conform the algorithms to the JCE framework.</p>344<p>Library home page: <a href=""http://www.bouncycastle.org/java.html"">http://www.bouncycastle.org/java.html</a></p>345<p>Path to dependency file: servicetalk/servicetalk-dns-discovery-netty/build.gradle</p>346<p>Path to vulnerable library: /tmp/ws-ua_20210122205702_PRGYMR/downloadResource_JSCHES/20210122211315/bcprov-jdk15-140.jar</p>347<p>348 349Dependency Hierarchy:350 - apacheds-protocol-dns-1.5.7.jar (Root Library)351 - apacheds-core-jndi-1.5.7.jar352 - apacheds-core-1.5.7.jar353 - :x: **bcprov-jdk15-140.jar** (Vulnerable Library)354<p>Found in HEAD commit: <a href=""https://github.com/tom9carthron1/servicetalk/commit/39fa324cb5853d697835802bdab3ffb89c559bc6"">39fa324cb5853d697835802bdab3ffb89c559bc6</a></p>355<p>Found in base branch: <b>main</b></p>356</p>357</details>358<p></p>359<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> Vulnerability Details</summary>360<p> 361 362Bouncy Castle BKS version 1 keystore (BKS-V1) files use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS-V1 keystore. All BKS-V1 keystores are vulnerable. Bouncy Castle release 1.47 introduces BKS version 2, which uses a 160-bit MAC.363 364<p>Publish Date: 2018-04-16365<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2018-5382>CVE-2018-5382</a></p>366</p>367</details>368<p></p>369<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>9.8</b>)</summary>370<p>371 372Base Score Metrics:373- Exploitability Metrics:374 - Attack Vector: Network375 - Attack Complexity: Low376 - Privileges Required: None377 - User Interaction: None378 - Scope: Unchanged379- Impact Metrics:380 - Confidentiality Impact: High381 - Integrity Impact: High382 - Availability Impact: High383</p>384For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.385</p>386</details>387<p></p>388<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>389<p>390 391<p>Type: Upgrade version</p>392<p>Origin: <a href=""https://vulners.com/cert/VU:306792"">https://vulners.com/cert/VU:306792</a></p>393<p>Release Date: 2018-04-16</p>394<p>Fix Resolution: org.bouncycastle:bcprov-ext-jdk14:1.47,org.bouncycastle:bcprov-ext-jdk15on:1.47,org.bouncycastle:bcprov-jdk14:1.47</p>395 396</p>397</details>398<p></p>399 400<!-- <REMEDIATE>{""isOpenPROnVulnerability"":false,""isPackageBased"":true,""isDefaultBranch"":true,""packages"":[{""packageType"":""Java"",""groupId"":""bouncycastle"",""packageName"":""bcprov-jdk15"",""packageVersion"":""140"",""isTransitiveDependency"":true,""dependencyTree"":""org.apache.directory.server:apacheds-protocol-dns:1.5.7;org.apache.directory.server:apacheds-core-jndi:1.5.7;org.apache.directory.server:apacheds-core:1.5.7;bouncycastle:bcprov-jdk15:140"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""org.bouncycastle:bcprov-ext-jdk14:1.47,org.bouncycastle:bcprov-ext-jdk15on:1.47,org.bouncycastle:bcprov-jdk14:1.47""}],""vulnerabilityIdentifier"":""CVE-2018-5382"",""vulnerabilityDetails"":""Bouncy Castle BKS version 1 keystore (BKS-V1) files use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS-V1 keystore. All BKS-V1 keystores are vulnerable. Bouncy Castle release 1.47 introduces BKS version 2, which uses a 160-bit MAC."",""vulnerabilityUrl"":""https://vuln.whitesourcesoftware.com/vulnerability/CVE-2018-5382"",""cvss3Severity"":""high"",""cvss3Score"":""9.8"",""cvss3Metrics"":{""A"":""High"",""AC"":""Low"",""PR"":""None"",""S"":""Unchanged"",""C"":""High"",""UI"":""None"",""AV"":""Network"",""I"":""High""},""extraData"":{}}</REMEDIATE> -->",0,cve high detected in bcprov jar cve high severity vulnerability vulnerable library bcprov jar the bouncy castle crypto package is a java implementation of cryptographic algorithms the package is organised so that it contains a light weight api suitable for use in any environment including the newly released with the additional infrastructure to conform the algorithms to the jce framework library home page a href path to dependency file servicetalk servicetalk dns discovery netty build gradle path to vulnerable library tmp ws ua prgymr downloadresource jsches bcprov jar dependency hierarchy apacheds protocol dns jar root library apacheds core jndi jar apacheds core jar x bcprov jar vulnerable library found in head commit a href found in base branch main vulnerability details bouncy castle bks version keystore bks files use an hmac that is only bits long which can allow an attacker to compromise the integrity of a bks keystore all bks keystores are vulnerable bouncy castle release introduces bks version which uses a bit mac publish date url a href cvss score details base score metrics exploitability metrics attack vector network attack complexity low privileges required none user interaction none scope unchanged impact metrics confidentiality impact high integrity impact high availability impact high for more information on scores click a href suggested fix type upgrade version origin a href release date fix resolution org bouncycastle bcprov ext org bouncycastle bcprov ext org bouncycastle bcprov isopenpronvulnerability false ispackagebased true isdefaultbranch true packages vulnerabilityidentifier cve vulnerabilitydetails bouncy castle bks version keystore bks files use an hmac that is only bits long which can allow an attacker to compromise the integrity of a bks keystore all bks keystores are vulnerable bouncy castle release introduces bks version which uses a bit mac vulnerabilityurl ,040114175,17088660823.0,IssuesEvent,2021-07-08 14:46:19,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[PM] Password expired error message is displayed when logging in with default superadmin credentials,Bug P1 Participant manager Process: Reopened,"Steps:
4021. Login with default superadmin crdentials (updated by script)
4032. Observe the error message
404
405Actual: Password expired error message is displayed when logging in with default superadmin credentials
406
407Expected: Should login without any error message",1.0,"[PM] Password expired error message is displayed when logging in with default superadmin credentials - Steps:
4081. Login with default superadmin crdentials (updated by script)
4092. Observe the error message
410
411Actual: Password expired error message is displayed when logging in with default superadmin credentials
412
413Expected: Should login without any error message",1, password expired error message is displayed when logging in with default superadmin credentials steps login with default superadmin crdentials updated by script observe the error message actual password expired error message is displayed when logging in with default superadmin credentials expected should login without any error message,1414370982,10959557758.0,IssuesEvent,2019-11-27 11:40:32,WoWManiaUK/Blackwing-Lair,https://api.github.com/repos/WoWManiaUK/Blackwing-Lair,closed,[Spell] Trinket Heart of Ignazius,Class Fixed in Dev Priority-High,"**Links:**
415https://wowdata.buffed.de/item/Ruestung/Verschiedenes/Herz-von-Ignazius-59514
416
417**What is happening:**
418The haste on use wont stack up like the spellpower
419
420
421**What should happen:**
422The haste should stack up like spellpower
423
424
425Prove:
426Stack the spellpower buff and use the trinket u only get the haste from the first stack
427
428
429
430
431
432
433
434
435
436
437",1.0,"[Spell] Trinket Heart of Ignazius - **Links:**
438https://wowdata.buffed.de/item/Ruestung/Verschiedenes/Herz-von-Ignazius-59514
439
440**What is happening:**
441The haste on use wont stack up like the spellpower
442
443
444**What should happen:**
445The haste should stack up like spellpower
446
447
448Prove:
449Stack the spellpower buff and use the trinket u only get the haste from the first stack
450
451
452
453
454
455
456
457
458
459
460",0, trinket heart of ignazius links what is happening the haste on use wont stack up like the spellpower what should happen the haste should stack up like spellpower prove stack the spellpower buff and use the trinket u only get the haste from the first stack ,046135392,4652438602.0,IssuesEvent,2016-10-03 14:01:42,prdxn-org/tagster,https://api.github.com/repos/prdxn-org/tagster,closed,Device (iPhone/Nexus) - Instagram Users section - Long names are misaligned,bug Design development,"**Issue Images:**
462
463
464
465
466**What should happen:**
467
468Long names is misaligned. The two worlds should be one below the other and aligned.",1.0,"Device (iPhone/Nexus) - Instagram Users section - Long names are misaligned - **Issue Images:**
469
470
471
472
473**What should happen:**
474
475Long names is misaligned. The two worlds should be one below the other and aligned.",0,device iphone nexus instagram users section long names are misaligned issue images what should happen long names is misaligned the two worlds should be one below the other and aligned ,0476181447,14020586132.0,IssuesEvent,2020-10-29 19:55:04,ISISScientificComputing/autoreduce,https://api.github.com/repos/ISISScientificComputing/autoreduce,opened,DataArchiveCreator prevents changes to settings.py,:key: Testing,"Issue raised by: [developer]
477
478### What?
479This is pretty convoluted to explain so I will try to bullet point it
480- `queue_processors/autoreduction_processor/test_settings.py` has 2 settings `ceph_directory` and `scripts_directory`. (As of right now there is also a comment above them that shows the settings used for the dev node and probably prod)
481- In `test_end_to_end.py` the class `DataArchiveCreator` is used to setup a fake data archive for storing datafiles/scripts/etc.
482- The `DataArchiveCreator` will only set up a directory that matches the current value in `test_settings.py` This means 2 different things:
483 * If those settings are ever changed `test_end_to_end.py` will break, as the `DataArchiveCreator` is not using the setting but is hardcoded to create a directory matching the setting as it exists right now.
484 * The production and development builds would technically fail these 2 end to end test cases
485 - The docstring for `DataArchiveCreator` also claims to produce an archive identical to isis data archive. It doesn't
486
487### Where?
488Settings at `queue_processors/autoreduction_processor/test_settings.py`
489Archive creator at `utils/data_archive/data_archive_creator.py`
490tests at `systemtests/test_end_to_end.py`
491
492### How?
493A need to change the settings revealed this.
494
495### Reproducible?
496[Yes]
497Change the setting and these 2 tests will fail.
498
499### How to test the issue is resolved
500The DataArchiveCreator should create a data archive based on the 2 settings from the settings file, not hard coded location. The end to end tests should then be able to pass on any environment (including dev and prod in theory)
501",1.0,"DataArchiveCreator prevents changes to settings.py - Issue raised by: [developer]
502
503### What?
504This is pretty convoluted to explain so I will try to bullet point it
505- `queue_processors/autoreduction_processor/test_settings.py` has 2 settings `ceph_directory` and `scripts_directory`. (As of right now there is also a comment above them that shows the settings used for the dev node and probably prod)
506- In `test_end_to_end.py` the class `DataArchiveCreator` is used to setup a fake data archive for storing datafiles/scripts/etc.
507- The `DataArchiveCreator` will only set up a directory that matches the current value in `test_settings.py` This means 2 different things:
508 * If those settings are ever changed `test_end_to_end.py` will break, as the `DataArchiveCreator` is not using the setting but is hardcoded to create a directory matching the setting as it exists right now.
509 * The production and development builds would technically fail these 2 end to end test cases
510 - The docstring for `DataArchiveCreator` also claims to produce an archive identical to isis data archive. It doesn't
511
512### Where?
513Settings at `queue_processors/autoreduction_processor/test_settings.py`
514Archive creator at `utils/data_archive/data_archive_creator.py`
515tests at `systemtests/test_end_to_end.py`
516
517### How?
518A need to change the settings revealed this.
519
520### Reproducible?
521[Yes]
522Change the setting and these 2 tests will fail.
523
524### How to test the issue is resolved
525The DataArchiveCreator should create a data archive based on the 2 settings from the settings file, not hard coded location. The end to end tests should then be able to pass on any environment (including dev and prod in theory)
526",0,dataarchivecreator prevents changes to settings py issue raised by what this is pretty convoluted to explain so i will try to bullet point it queue processors autoreduction processor test settings py has settings ceph directory and scripts directory as of right now there is also a comment above them that shows the settings used for the dev node and probably prod in test end to end py the class dataarchivecreator is used to setup a fake data archive for storing datafiles scripts etc the dataarchivecreator will only set up a directory that matches the current value in test settings py this means different things if those settings are ever changed test end to end py will break as the dataarchivecreator is not using the setting but is hardcoded to create a directory matching the setting as it exists right now the production and development builds would technically fail these end to end test cases the docstring for dataarchivecreator also claims to produce an archive identical to isis data archive it doesn t where settings at queue processors autoreduction processor test settings py archive creator at utils data archive data archive creator py tests at systemtests test end to end py how a need to change the settings revealed this reproducible change the setting and these tests will fail how to test the issue is resolved the dataarchivecreator should create a data archive based on the settings from the settings file not hard coded location the end to end tests should then be able to pass on any environment including dev and prod in theory ,052718502,24551247947.0,IssuesEvent,2022-10-12 12:46:50,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[iOS] Study activities screen > 'No activities found' error message getting displayed for few seconds in the following screen,Bug P1 iOS Process: Fixed Process: Tested dev,"Steps:
5281. Sign up or sign in to the mobile app
5292. Enroll to the study
5303. Navigate to study activities screen and observe
531
532AR: 'No activities found' error message getting displayed for few seconds
533ER: 'No activities found' error message should not get displayed
534
535[Issue observed when user enters to study activities screen for the fist time after enrolling into the study]
536
537https://user-images.githubusercontent.com/71445210/182616320-5f56a357-7011-4c49-b0b0-b6ebdae1ff9a.mp4
538
539
540",2.0,"[iOS] Study activities screen > 'No activities found' error message getting displayed for few seconds in the following screen - Steps:
5411. Sign up or sign in to the mobile app
5422. Enroll to the study
5433. Navigate to study activities screen and observe
544
545AR: 'No activities found' error message getting displayed for few seconds
546ER: 'No activities found' error message should not get displayed
547
548[Issue observed when user enters to study activities screen for the fist time after enrolling into the study]
549
550https://user-images.githubusercontent.com/71445210/182616320-5f56a357-7011-4c49-b0b0-b6ebdae1ff9a.mp4
551
552
553",1, study activities screen no activities found error message getting displayed for few seconds in the following screen steps sign up or sign in to the mobile app enroll to the study navigate to study activities screen and observe ar no activities found error message getting displayed for few seconds er no activities found error message should not get displayed ,1554488450,14077641873.0,IssuesEvent,2020-11-04 12:21:37,Scholar-6/brillder,https://api.github.com/repos/Scholar-6/brillder,closed,"Mobile: If click play a brick, make full screen; add fullscreen options in dropdown",High Level Priority Onboarding | UX,"- [x] play to fullscreeen
555
556- [x] Dropdown: Enter Full Screen, Feather maximize
557
558- [x] Dropdown when in Full Screen: Exit Full Screen, Feather maximize
559",1.0,"Mobile: If click play a brick, make full screen; add fullscreen options in dropdown - - [x] play to fullscreeen
560
561- [x] Dropdown: Enter Full Screen, Feather maximize
562
563- [x] Dropdown when in Full Screen: Exit Full Screen, Feather maximize
564",0,mobile if click play a brick make full screen add fullscreen options in dropdown play to fullscreeen dropdown enter full screen feather maximize dropdown when in full screen exit full screen feather maximize ,056512465,14937391216.0,IssuesEvent,2021-01-25 14:35:06,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,"[Android] [Audit Logs] ""userID"" is displayed null for the events",Android Bug P2 Process: Fixed Process: Tested dev,"Event:-
5661. PASSWORD_RESET_SUCCEEDED
567
568Sample snippet
569```
570{
571 ""insertId"": ""1xxk52ag3ixdmsf"",
572 ""jsonPayload"": {
573 ""description"": null,
574 ""resourceServer"": ""PARTICIPANT USER DATASTORE"",
575 ""appId"": ""BTCDEV001"",
576 ""userIp"": ""157.45.162.176"",
577 ""destination"": ""SCIM AUTH SERVER"",
578 ""mobilePlatform"": ""ANDROID"",
579 ""occurred"": 1611240030322,
580 ""userAccessLevel"": null,
581 ""siteId"": null,
582 ""participantId"": null,
583 ""destinationApplicationVersion"": ""1.0"",
584 ""sourceApplicationVersion"": ""1.0"",
585 ""correlationId"": ""SCJfbJLx83G45JpSFBeYYtE6tEESvAuvJPNkiqshEiPJfV8BhP"",
586 ""studyId"": null,
587 ""appVersion"": ""1.0.58"",
588 ""userId"": null,
589 ""source"": ""MOBILE APPS"",
590 ""eventCode"": ""PASSWORD_RESET_SUCCEEDED"",
591 ""platformVersion"": ""1.0"",
592 ""studyVersion"": null
593 },
594 ""resource"": {
595 ""type"": ""global"",
596 ""labels"": {
597 ""project_id"": ""mystudies-open-impl-track1-dev""
598 }
599 },
600 ""timestamp"": ""2021-01-21T14:40:30.322Z"",
601 ""severity"": ""INFO"",
602 ""logName"": ""projects/mystudies-open-impl-track1-dev/logs/application-audit-log"",
603 ""receiveTimestamp"": ""2021-01-21T14:40:30.452503878Z""
604}
605```",2.0,"[Android] [Audit Logs] ""userID"" is displayed null for the events - Event:-
6061. PASSWORD_RESET_SUCCEEDED
607
608Sample snippet
609```
610{
611 ""insertId"": ""1xxk52ag3ixdmsf"",
612 ""jsonPayload"": {
613 ""description"": null,
614 ""resourceServer"": ""PARTICIPANT USER DATASTORE"",
615 ""appId"": ""BTCDEV001"",
616 ""userIp"": ""157.45.162.176"",
617 ""destination"": ""SCIM AUTH SERVER"",
618 ""mobilePlatform"": ""ANDROID"",
619 ""occurred"": 1611240030322,
620 ""userAccessLevel"": null,
621 ""siteId"": null,
622 ""participantId"": null,
623 ""destinationApplicationVersion"": ""1.0"",
624 ""sourceApplicationVersion"": ""1.0"",
625 ""correlationId"": ""SCJfbJLx83G45JpSFBeYYtE6tEESvAuvJPNkiqshEiPJfV8BhP"",
626 ""studyId"": null,
627 ""appVersion"": ""1.0.58"",
628 ""userId"": null,
629 ""source"": ""MOBILE APPS"",
630 ""eventCode"": ""PASSWORD_RESET_SUCCEEDED"",
631 ""platformVersion"": ""1.0"",
632 ""studyVersion"": null
633 },
634 ""resource"": {
635 ""type"": ""global"",
636 ""labels"": {
637 ""project_id"": ""mystudies-open-impl-track1-dev""
638 }
639 },
640 ""timestamp"": ""2021-01-21T14:40:30.322Z"",
641 ""severity"": ""INFO"",
642 ""logName"": ""projects/mystudies-open-impl-track1-dev/logs/application-audit-log"",
643 ""receiveTimestamp"": ""2021-01-21T14:40:30.452503878Z""
644}
645```",1, userid is displayed null for the events event password reset succeeded sample snippet insertid jsonpayload description null resourceserver participant user datastore appid userip destination scim auth server mobileplatform android occurred useraccesslevel null siteid null participantid null destinationapplicationversion sourceapplicationversion correlationid studyid null appversion userid null source mobile apps eventcode password reset succeeded platformversion studyversion null resource type global labels project id mystudies open impl dev timestamp severity info logname projects mystudies open impl dev logs application audit log receivetimestamp ,164618711,24603783650.0,IssuesEvent,2022-10-14 14:32:18,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[DID] [Discard FHIR after DID Enabled] Patient resource > Value of the 'active' key is not updating to the 'false' when participant is withdrawn from the study or deactivates his/her account,Bug P1 Response datastore Process: Fixed Process: Tested dev,"AR: Patient resource > Value of the 'active' key is not updating to the 'false' when the participant is withdrawn from the study or deactivates his/her account
647ER: The value of the 'active' key should be changed from true to false when the participant withdraws from the study
648
649
650
651
652",2.0,"[DID] [Discard FHIR after DID Enabled] Patient resource > Value of the 'active' key is not updating to the 'false' when participant is withdrawn from the study or deactivates his/her account - AR: Patient resource > Value of the 'active' key is not updating to the 'false' when the participant is withdrawn from the study or deactivates his/her account
653ER: The value of the 'active' key should be changed from true to false when the participant withdraws from the study
654
655
656
657
658",1, patient resource value of the active key is not updating to the false when participant is withdrawn from the study or deactivates his her account ar patient resource value of the active key is not updating to the false when the participant is withdrawn from the study or deactivates his her account er the value of the active key should be changed from true to false when the participant withdraws from the study ,165911829,14655267750.0,IssuesEvent,2020-12-28 10:36:27,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[PM] [Dev] getting 500 error when site permission is not given,Bug P1 Participant manager Process: Dev Process: Fixed Process: Tested QA Process: Tested dev,"Getting 500 error when site permission is not given
660
661AR : Displaying general error message
662ER : 'No sites found' (EC_0070) should be displayed
663
664
665
666",4.0,"[PM] [Dev] getting 500 error when site permission is not given - Getting 500 error when site permission is not given
667
668AR : Displaying general error message
669ER : 'No sites found' (EC_0070) should be displayed
670
671
672
673",1, getting error when site permission is not given getting error when site permission is not given ar displaying general error message er no sites found ec should be displayed ,167418513,24551620218.0,IssuesEvent,2022-10-12 13:02:26,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[iOS] Activities list screen > All the activities status is showing as 'Missed',Bug Blocker P0 iOS Process: Fixed Process: Tested dev,"Activities list screen > All the activities status is showing as 'Missed'
675
676Note:
6771. Issue observe in the latest build 3.0(125)
678
679
680",2.0,"[iOS] Activities list screen > All the activities status is showing as 'Missed' - Activities list screen > All the activities status is showing as 'Missed'
681
682Note:
6831. Issue observe in the latest build 3.0(125)
684
685
686",1, activities list screen all the activities status is showing as missed activities list screen all the activities status is showing as missed note issue observe in the latest build ,168713043,15385236409.0,IssuesEvent,2021-03-03 06:12:05,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,Stackdriver logging - client is not shut down properly,Bug P1 Process: Fixed Process: Release 2,"Seeing in logs:
688```
689SEVERE [http-nio-8080-exec-4] io.grpc.internal.ManagedChannelOrphanWrapper$ManagedChannelReference.cleanQueue *~*~*~ Channel ManagedChannelImpl{logId=5, target=logging.googleapis.com:443} was not shutdown properly!!! ~*~*~*
690 Make sure to call shutdown()/shutdownNow() and wait until awaitTermination() returns true.
691java.lang.RuntimeException: ManagedChannel allocation site
692 at io.grpc.internal.ManagedChannelOrphanWrapper$ManagedChannelReference.<init>(ManagedChannelOrphanWrapper.java:94)
693 at io.grpc.internal.ManagedChannelOrphanWrapper.<init>(ManagedChannelOrphanWrapper.java:52)
694 at io.grpc.internal.ManagedChannelOrphanWrapper.<init>(ManagedChannelOrphanWrapper.java:43)
695 at io.grpc.internal.AbstractManagedChannelImplBuilder.build(AbstractManagedChannelImplBuilder.java:518)
696 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider.createSingleChannel(InstantiatingGrpcChannelProvider.java:304)
697 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider.access$1500(InstantiatingGrpcChannelProvider.java:71)
698 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider$1.createSingleChannel(InstantiatingGrpcChannelProvider.java:202)
699 at com.google.api.gax.grpc.ChannelPool.create(ChannelPool.java:72)
700 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider.createChannel(InstantiatingGrpcChannelProvider.java:209)
701 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider.getTransportChannel(InstantiatingGrpcChannelProvider.java:192)
702 at com.google.api.gax.rpc.ClientContext.create(ClientContext.java:155)
703 at com.google.api.gax.rpc.ClientContext.create(ClientContext.java:122)
704 at com.google.cloud.logging.spi.v2.GrpcLoggingRpc.<init>(GrpcLoggingRpc.java:132)
705 at com.google.cloud.logging.LoggingOptions$DefaultLoggingRpcFactory.create(LoggingOptions.java:61)
706 at com.google.cloud.logging.LoggingOptions$DefaultLoggingRpcFactory.create(LoggingOptions.java:55)
707 at com.google.cloud.ServiceOptions.getRpc(ServiceOptions.java:538)
708 at com.google.cloud.logging.LoggingOptions.getLoggingRpcV2(LoggingOptions.java:129)
709 at com.google.cloud.logging.LoggingImpl.<init>(LoggingImpl.java:109)
710 at com.google.cloud.logging.LoggingOptions$DefaultLoggingFactory.create(LoggingOptions.java:46)
711 at com.google.cloud.logging.LoggingOptions$DefaultLoggingFactory.create(LoggingOptions.java:41)
712 at com.google.cloud.ServiceOptions.getService(ServiceOptions.java:518)
713 at com.google.cloud.healthcare.fdamystudies.service.AuditEventServiceImpl.postAuditLogEvent(AuditEventServiceImpl.java:43)
714 at com.google.cloud.healthcare.fdamystudies.common.UserMgmntAuditHelper.logEvent(UserMgmntAuditHelper.java:45)
715 at com.google.cloud.healthcare.fdamystudies.common.UserMgmntAuditHelper.logEvent(UserMgmntAuditHelper.java:30)
716 at com.google.cloud.healthcare.fdamystudies.service.UserRegistrationServiceImpl.register(UserRegistrationServiceImpl.java:96)
717 at com.google.cloud.healthcare.fdamystudies.service.UserRegistrationServiceImpl$$FastClassBySpringCGLIB$$ce6a0d62.invoke(<generated>)
718```
719",2.0,"Stackdriver logging - client is not shut down properly - Seeing in logs:
720```
721SEVERE [http-nio-8080-exec-4] io.grpc.internal.ManagedChannelOrphanWrapper$ManagedChannelReference.cleanQueue *~*~*~ Channel ManagedChannelImpl{logId=5, target=logging.googleapis.com:443} was not shutdown properly!!! ~*~*~*
722 Make sure to call shutdown()/shutdownNow() and wait until awaitTermination() returns true.
723java.lang.RuntimeException: ManagedChannel allocation site
724 at io.grpc.internal.ManagedChannelOrphanWrapper$ManagedChannelReference.<init>(ManagedChannelOrphanWrapper.java:94)
725 at io.grpc.internal.ManagedChannelOrphanWrapper.<init>(ManagedChannelOrphanWrapper.java:52)
726 at io.grpc.internal.ManagedChannelOrphanWrapper.<init>(ManagedChannelOrphanWrapper.java:43)
727 at io.grpc.internal.AbstractManagedChannelImplBuilder.build(AbstractManagedChannelImplBuilder.java:518)
728 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider.createSingleChannel(InstantiatingGrpcChannelProvider.java:304)
729 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider.access$1500(InstantiatingGrpcChannelProvider.java:71)
730 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider$1.createSingleChannel(InstantiatingGrpcChannelProvider.java:202)
731 at com.google.api.gax.grpc.ChannelPool.create(ChannelPool.java:72)
732 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider.createChannel(InstantiatingGrpcChannelProvider.java:209)
733 at com.google.api.gax.grpc.InstantiatingGrpcChannelProvider.getTransportChannel(InstantiatingGrpcChannelProvider.java:192)
734 at com.google.api.gax.rpc.ClientContext.create(ClientContext.java:155)
735 at com.google.api.gax.rpc.ClientContext.create(ClientContext.java:122)
736 at com.google.cloud.logging.spi.v2.GrpcLoggingRpc.<init>(GrpcLoggingRpc.java:132)
737 at com.google.cloud.logging.LoggingOptions$DefaultLoggingRpcFactory.create(LoggingOptions.java:61)
738 at com.google.cloud.logging.LoggingOptions$DefaultLoggingRpcFactory.create(LoggingOptions.java:55)
739 at com.google.cloud.ServiceOptions.getRpc(ServiceOptions.java:538)
740 at com.google.cloud.logging.LoggingOptions.getLoggingRpcV2(LoggingOptions.java:129)
741 at com.google.cloud.logging.LoggingImpl.<init>(LoggingImpl.java:109)
742 at com.google.cloud.logging.LoggingOptions$DefaultLoggingFactory.create(LoggingOptions.java:46)
743 at com.google.cloud.logging.LoggingOptions$DefaultLoggingFactory.create(LoggingOptions.java:41)
744 at com.google.cloud.ServiceOptions.getService(ServiceOptions.java:518)
745 at com.google.cloud.healthcare.fdamystudies.service.AuditEventServiceImpl.postAuditLogEvent(AuditEventServiceImpl.java:43)
746 at com.google.cloud.healthcare.fdamystudies.common.UserMgmntAuditHelper.logEvent(UserMgmntAuditHelper.java:45)
747 at com.google.cloud.healthcare.fdamystudies.common.UserMgmntAuditHelper.logEvent(UserMgmntAuditHelper.java:30)
748 at com.google.cloud.healthcare.fdamystudies.service.UserRegistrationServiceImpl.register(UserRegistrationServiceImpl.java:96)
749 at com.google.cloud.healthcare.fdamystudies.service.UserRegistrationServiceImpl$$FastClassBySpringCGLIB$$ce6a0d62.invoke(<generated>)
750```
751",1,stackdriver logging client is not shut down properly seeing in logs severe io grpc internal managedchannelorphanwrapper managedchannelreference cleanqueue channel managedchannelimpl logid target logging googleapis com was not shutdown properly make sure to call shutdown shutdownnow and wait until awaittermination returns true java lang runtimeexception managedchannel allocation site at io grpc internal managedchannelorphanwrapper managedchannelreference managedchannelorphanwrapper java at io grpc internal managedchannelorphanwrapper managedchannelorphanwrapper java at io grpc internal managedchannelorphanwrapper managedchannelorphanwrapper java at io grpc internal abstractmanagedchannelimplbuilder build abstractmanagedchannelimplbuilder java at com google api gax grpc instantiatinggrpcchannelprovider createsinglechannel instantiatinggrpcchannelprovider java at com google api gax grpc instantiatinggrpcchannelprovider access instantiatinggrpcchannelprovider java at com google api gax grpc instantiatinggrpcchannelprovider createsinglechannel instantiatinggrpcchannelprovider java at com google api gax grpc channelpool create channelpool java at com google api gax grpc instantiatinggrpcchannelprovider createchannel instantiatinggrpcchannelprovider java at com google api gax grpc instantiatinggrpcchannelprovider gettransportchannel instantiatinggrpcchannelprovider java at com google api gax rpc clientcontext create clientcontext java at com google api gax rpc clientcontext create clientcontext java at com google cloud logging spi grpcloggingrpc grpcloggingrpc java at com google cloud logging loggingoptions defaultloggingrpcfactory create loggingoptions java at com google cloud logging loggingoptions defaultloggingrpcfactory create loggingoptions java at com google cloud serviceoptions getrpc serviceoptions java at com google cloud logging loggingoptions loggingoptions java at com google cloud logging loggingimpl loggingimpl java at com google cloud logging loggingoptions defaultloggingfactory create loggingoptions java at com google cloud logging loggingoptions defaultloggingfactory create loggingoptions java at com google cloud serviceoptions getservice serviceoptions java at com google cloud healthcare fdamystudies service auditeventserviceimpl postauditlogevent auditeventserviceimpl java at com google cloud healthcare fdamystudies common usermgmntaudithelper logevent usermgmntaudithelper java at com google cloud healthcare fdamystudies common usermgmntaudithelper logevent usermgmntaudithelper java at com google cloud healthcare fdamystudies service userregistrationserviceimpl register userregistrationserviceimpl java at com google cloud healthcare fdamystudies service userregistrationserviceimpl fastclassbyspringcglib invoke ,17525830,7346549693.0,IssuesEvent,2018-03-07 21:06:41,Microsoft/vscode-cpptools,https://api.github.com/repos/Microsoft/vscode-cpptools,closed,VSCode C/C++ Extension(ms-vscode.cpptools) can be cached?,Language Service bug,"As my usage, I usually open 2 or more Linux Kernel Source projects in vscode, it's very huge.
753When I open vscode, ms-vscode.cpptools will auto start preparation of C/C++ IntelliSense, such as symbol search ing, goto defination and so on.
754But as I say, the project of kernel source code is very huge and ms-vscode.cpptools will take a lot of time to finish. Every time I open vscode, this preparation job will run again and take a lot of time.
755I'm thinking that ms-vscode.cpptools should add cache support for a project.",1.0,"VSCode C/C++ Extension(ms-vscode.cpptools) can be cached? - As my usage, I usually open 2 or more Linux Kernel Source projects in vscode, it's very huge.
756When I open vscode, ms-vscode.cpptools will auto start preparation of C/C++ IntelliSense, such as symbol search ing, goto defination and so on.
757But as I say, the project of kernel source code is very huge and ms-vscode.cpptools will take a lot of time to finish. Every time I open vscode, this preparation job will run again and take a lot of time.
758I'm thinking that ms-vscode.cpptools should add cache support for a project.",0,vscode c c extension ms vscode cpptools can be cached as my usage i usually open or more linux kernel source projects in vscode it s very huge when i open vscode ms vscode cpptools will auto start preparation of c c intellisense such as symbol search ing goto defination and so on but as i say the project of kernel source code is very huge and ms vscode cpptools will take a lot of time to finish every time i open vscode this preparation job will run again and take a lot of time i m thinking that ms vscode cpptools should add cache support for a project ,075912441,14933263769.0,IssuesEvent,2021-01-25 08:59:16,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,Password criteria display should be consistent,Bug P2 Participant manager Process: Tested dev,"Password criteria should be consistent
760ER : ' Your password must be at least 8 characters long and contain lower case, upper case, numeric and special characters' should be displayed in the following screens
7611. Change Password screen
7622. Setup password screen
763
764
765
766",1.0,"Password criteria display should be consistent - Password criteria should be consistent
767ER : ' Your password must be at least 8 characters long and contain lower case, upper case, numeric and special characters' should be displayed in the following screens
7681. Change Password screen
7692. Setup password screen
770
771
772
773",1,password criteria display should be consistent password criteria should be consistent er your password must be at least characters long and contain lower case upper case numeric and special characters should be displayed in the following screens change password screen setup password screen ,177422933,7247259294.0,IssuesEvent,2018-02-15 01:36:26,jaagr/polybar,https://api.github.com/repos/jaagr/polybar,closed,xpp/proto build error on openSUSE tumbleweed,build,"Hello
775
776When I try to build polybar, I get this error. I have tried playing around with different dependencies and versions of polybar, but it just will not go away.
777
778Error:
779
780```
781[ 1%] Generating ../../../lib/xpp/include/xpp/proto/x.hpp
782Traceback (most recent call last):
783 File ""/home/james/mysuseconfig/polybar/lib/xpp/generators/cpp_client.py"", line 3163, in <module>
784 from xcbgen.state import Module
785 File ""/usr/lib/python3.6/site-packages/xcbgen/state.py"", line 7, in <module>
786 from xcbgen import matcher
787 File ""/usr/lib/python3.6/site-packages/xcbgen/matcher.py"", line 12, in <module>
788 from xcbgen.xtypes import *
789 File ""/usr/lib/python3.6/site-packages/xcbgen/xtypes.py"", line 1201, in <module>
790 class EventStruct(Union):
791 File ""/usr/lib/python3.6/site-packages/xcbgen/xtypes.py"", line 1219, in EventStruct
792 out = __main__.output['eventstruct']
793KeyError: 'eventstruct'
794make[2]: *** [lib/xpp/CMakeFiles/xpp.dir/build.make:70: ../lib/xpp/include/xpp/proto/x.hpp] Error 1
795make[2]: *** Deleting file '../lib/xpp/include/xpp/proto/x.hpp'
796make[1]: *** [CMakeFiles/Makefile2:402: lib/xpp/CMakeFiles/xpp.dir/all] Error 2
797make: *** [Makefile:130: all] Error 2
798```
799
800James",1.0,"xpp/proto build error on openSUSE tumbleweed - Hello
801
802When I try to build polybar, I get this error. I have tried playing around with different dependencies and versions of polybar, but it just will not go away.
803
804Error:
805
806```
807[ 1%] Generating ../../../lib/xpp/include/xpp/proto/x.hpp
808Traceback (most recent call last):
809 File ""/home/james/mysuseconfig/polybar/lib/xpp/generators/cpp_client.py"", line 3163, in <module>
810 from xcbgen.state import Module
811 File ""/usr/lib/python3.6/site-packages/xcbgen/state.py"", line 7, in <module>
812 from xcbgen import matcher
813 File ""/usr/lib/python3.6/site-packages/xcbgen/matcher.py"", line 12, in <module>
814 from xcbgen.xtypes import *
815 File ""/usr/lib/python3.6/site-packages/xcbgen/xtypes.py"", line 1201, in <module>
816 class EventStruct(Union):
817 File ""/usr/lib/python3.6/site-packages/xcbgen/xtypes.py"", line 1219, in EventStruct
818 out = __main__.output['eventstruct']
819KeyError: 'eventstruct'
820make[2]: *** [lib/xpp/CMakeFiles/xpp.dir/build.make:70: ../lib/xpp/include/xpp/proto/x.hpp] Error 1
821make[2]: *** Deleting file '../lib/xpp/include/xpp/proto/x.hpp'
822make[1]: *** [CMakeFiles/Makefile2:402: lib/xpp/CMakeFiles/xpp.dir/all] Error 2
823make: *** [Makefile:130: all] Error 2
824```
825
826James",0,xpp proto build error on opensuse tumbleweed hello when i try to build polybar i get this error i have tried playing around with different dependencies and versions of polybar but it just will not go away error generating lib xpp include xpp proto x hpp traceback most recent call last file home james mysuseconfig polybar lib xpp generators cpp client py line in from xcbgen state import module file usr lib site packages xcbgen state py line in from xcbgen import matcher file usr lib site packages xcbgen matcher py line in from xcbgen xtypes import file usr lib site packages xcbgen xtypes py line in class eventstruct union file usr lib site packages xcbgen xtypes py line in eventstruct out main output keyerror eventstruct make error make deleting file lib xpp include xpp proto x hpp make error make error james,08272218,2603991278.0,IssuesEvent,2015-02-24 19:06:41,chrsmith/nishazi6,https://api.github.com/repos/chrsmith/nishazi6,opened,沈阳疱疹的治疗办法,auto-migrated Priority-Medium Type-Defect,"```828沈阳疱疹的治疗办法〓沈陽軍區政治部醫院性病〓TEL:024-31028293308〓成立于1946年,68年專注于性傳播疾病的研究和治療。位�830��沈陽市沈河區二緯路32號。是一所與新中國同建立共輝煌的�831��史悠久、設備精良、技術權威、專家云集,是預防、保健、832醫療、科研康復為一體的綜合性醫院。是國家首批公立甲等��833�隊醫院、全國首批醫療規范定點單位,是第四軍醫大學、東�834��大學等知名高等院校的教學醫院。曾被中國人民解放軍空軍835后勤部衛生部評為衛生工作先進單位,先后兩次榮立集體二��836�功。837```838 839-----840Original issue reported on code.google.com by `q964105...@gmail.com` on 4 Jun 2014 at 8:31",1.0,"沈阳疱疹的治疗办法 - ```841沈阳疱疹的治疗办法〓沈陽軍區政治部醫院性病〓TEL:024-31028423308〓成立于1946年,68年專注于性傳播疾病的研究和治療。位�843��沈陽市沈河區二緯路32號。是一所與新中國同建立共輝煌的�844��史悠久、設備精良、技術權威、專家云集,是預防、保健、845醫療、科研康復為一體的綜合性醫院。是國家首批公立甲等��846�隊醫院、全國首批醫療規范定點單位,是第四軍醫大學、東�847��大學等知名高等院校的教學醫院。曾被中國人民解放軍空軍848后勤部衛生部評為衛生工作先進單位,先后兩次榮立集體二��849�功。850```851 852-----853Original issue reported on code.google.com by `q964105...@gmail.com` on 4 Jun 2014 at 8:31",0,沈阳疱疹的治疗办法 沈阳疱疹的治疗办法〓沈陽軍區政治部醫院性病〓tel: 〓 , 。位� �� 。是一所與新中國同建立共輝煌的� ��史悠久、設備精良、技術權威、專家云集,是預防、保健、 醫療、科研康復為一體的綜合性醫院。是國家首批公立甲等�� �隊醫院、全國首批醫療規范定點單位,是第四軍醫大學、東� ��大學等知名高等院校的教學醫院。曾被中國人民解放軍空軍 后勤部衛生部評為衛生工作先進單位,先后兩次榮立集體二�� �功。 original issue reported on code google com by gmail com on jun at ,085474232,15325437330.0,IssuesEvent,2021-02-26 01:18:44,idonthaveafifaaddiction/MapLoom,https://api.github.com/repos/idonthaveafifaaddiction/MapLoom,opened,WS-2020-0091 (High) detected in http-proxy-0.10.4.tgz,security vulnerability,"## WS-2020-0091 - High Severity Vulnerability855<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>http-proxy-0.10.4.tgz</b></p></summary>856 857<p>A full-featured http reverse proxy for node.js</p>858<p>Library home page: <a href=""https://registry.npmjs.org/http-proxy/-/http-proxy-0.10.4.tgz"">https://registry.npmjs.org/http-proxy/-/http-proxy-0.10.4.tgz</a></p>859<p>Path to dependency file: MapLoom/vendor/angular-ui-router/package.json</p>860<p>Path to vulnerable library: MapLoom/vendor/angular-ui-router/node_modules/http-proxy/package.json</p>861<p>862 863Dependency Hierarchy:864 - karma-0.10.10.tgz (Root Library)865 - :x: **http-proxy-0.10.4.tgz** (Vulnerable Library)866<p>Found in base branch: <b>master</b></p>867</p>868</details>869<p></p>870<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> Vulnerability Details</summary>871<p> 872 873Versions of http-proxy prior to 1.18.1 are vulnerable to Denial of Service. An HTTP request with a long body triggers an ERR_HTTP_HEADERS_SENT unhandled exception that crashes the proxy server. This is only possible when the proxy server sets headers in the proxy request using the proxyReq.setHeader function.874 875<p>Publish Date: 2020-05-14876<p>URL: <a href=https://github.com/http-party/node-http-proxy/pull/1447>WS-2020-0091</a></p>877</p>878</details>879<p></p>880<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>7.5</b>)</summary>881<p>882 883Base Score Metrics:884- Exploitability Metrics:885 - Attack Vector: Network886 - Attack Complexity: Low887 - Privileges Required: None888 - User Interaction: None889 - Scope: Unchanged890- Impact Metrics:891 - Confidentiality Impact: None892 - Integrity Impact: None893 - Availability Impact: High894</p>895For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.896</p>897</details>898<p></p>899<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>900<p>901 902<p>Type: Upgrade version</p>903<p>Origin: <a href=""https://www.npmjs.com/advisories/1486"">https://www.npmjs.com/advisories/1486</a></p>904<p>Release Date: 2020-05-26</p>905<p>Fix Resolution: http-proxy - 1.18.1 </p>906 907</p>908</details>909<p></p>910 911<!-- <REMEDIATE>{""isOpenPROnVulnerability"":false,""isPackageBased"":true,""isDefaultBranch"":true,""packages"":[{""packageType"":""javascript/Node.js"",""packageName"":""http-proxy"",""packageVersion"":""0.10.4"",""packageFilePaths"":[""/vendor/angular-ui-router/package.json""],""isTransitiveDependency"":true,""dependencyTree"":""karma:0.10.10;http-proxy:0.10.4"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""http-proxy - 1.18.1 ""}],""baseBranches"":[""master""],""vulnerabilityIdentifier"":""WS-2020-0091"",""vulnerabilityDetails"":""Versions of http-proxy prior to 1.18.1 are vulnerable to Denial of Service. An HTTP request with a long body triggers an ERR_HTTP_HEADERS_SENT unhandled exception that crashes the proxy server. This is only possible when the proxy server sets headers in the proxy request using the proxyReq.setHeader function."",""vulnerabilityUrl"":""https://github.com/http-party/node-http-proxy/pull/1447"",""cvss3Severity"":""high"",""cvss3Score"":""7.5"",""cvss3Metrics"":{""A"":""High"",""AC"":""Low"",""PR"":""None"",""S"":""Unchanged"",""C"":""None"",""UI"":""None"",""AV"":""Network"",""I"":""None""},""extraData"":{}}</REMEDIATE> -->",True,"WS-2020-0091 (High) detected in http-proxy-0.10.4.tgz - ## WS-2020-0091 - High Severity Vulnerability912<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>http-proxy-0.10.4.tgz</b></p></summary>913 914<p>A full-featured http reverse proxy for node.js</p>915<p>Library home page: <a href=""https://registry.npmjs.org/http-proxy/-/http-proxy-0.10.4.tgz"">https://registry.npmjs.org/http-proxy/-/http-proxy-0.10.4.tgz</a></p>916<p>Path to dependency file: MapLoom/vendor/angular-ui-router/package.json</p>917<p>Path to vulnerable library: MapLoom/vendor/angular-ui-router/node_modules/http-proxy/package.json</p>918<p>919 920Dependency Hierarchy:921 - karma-0.10.10.tgz (Root Library)922 - :x: **http-proxy-0.10.4.tgz** (Vulnerable Library)923<p>Found in base branch: <b>master</b></p>924</p>925</details>926<p></p>927<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> Vulnerability Details</summary>928<p> 929 930Versions of http-proxy prior to 1.18.1 are vulnerable to Denial of Service. An HTTP request with a long body triggers an ERR_HTTP_HEADERS_SENT unhandled exception that crashes the proxy server. This is only possible when the proxy server sets headers in the proxy request using the proxyReq.setHeader function.931 932<p>Publish Date: 2020-05-14933<p>URL: <a href=https://github.com/http-party/node-http-proxy/pull/1447>WS-2020-0091</a></p>934</p>935</details>936<p></p>937<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>7.5</b>)</summary>938<p>939 940Base Score Metrics:941- Exploitability Metrics:942 - Attack Vector: Network943 - Attack Complexity: Low944 - Privileges Required: None945 - User Interaction: None946 - Scope: Unchanged947- Impact Metrics:948 - Confidentiality Impact: None949 - Integrity Impact: None950 - Availability Impact: High951</p>952For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.953</p>954</details>955<p></p>956<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>957<p>958 959<p>Type: Upgrade version</p>960<p>Origin: <a href=""https://www.npmjs.com/advisories/1486"">https://www.npmjs.com/advisories/1486</a></p>961<p>Release Date: 2020-05-26</p>962<p>Fix Resolution: http-proxy - 1.18.1 </p>963 964</p>965</details>966<p></p>967 968<!-- <REMEDIATE>{""isOpenPROnVulnerability"":false,""isPackageBased"":true,""isDefaultBranch"":true,""packages"":[{""packageType"":""javascript/Node.js"",""packageName"":""http-proxy"",""packageVersion"":""0.10.4"",""packageFilePaths"":[""/vendor/angular-ui-router/package.json""],""isTransitiveDependency"":true,""dependencyTree"":""karma:0.10.10;http-proxy:0.10.4"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""http-proxy - 1.18.1 ""}],""baseBranches"":[""master""],""vulnerabilityIdentifier"":""WS-2020-0091"",""vulnerabilityDetails"":""Versions of http-proxy prior to 1.18.1 are vulnerable to Denial of Service. An HTTP request with a long body triggers an ERR_HTTP_HEADERS_SENT unhandled exception that crashes the proxy server. This is only possible when the proxy server sets headers in the proxy request using the proxyReq.setHeader function."",""vulnerabilityUrl"":""https://github.com/http-party/node-http-proxy/pull/1447"",""cvss3Severity"":""high"",""cvss3Score"":""7.5"",""cvss3Metrics"":{""A"":""High"",""AC"":""Low"",""PR"":""None"",""S"":""Unchanged"",""C"":""None"",""UI"":""None"",""AV"":""Network"",""I"":""None""},""extraData"":{}}</REMEDIATE> -->",0,ws high detected in http proxy tgz ws high severity vulnerability vulnerable library http proxy tgz a full featured http reverse proxy for node js library home page a href path to dependency file maploom vendor angular ui router package json path to vulnerable library maploom vendor angular ui router node modules http proxy package json dependency hierarchy karma tgz root library x http proxy tgz vulnerable library found in base branch master vulnerability details versions of http proxy prior to are vulnerable to denial of service an http request with a long body triggers an err http headers sent unhandled exception that crashes the proxy server this is only possible when the proxy server sets headers in the proxy request using the proxyreq setheader function publish date url a href cvss score details base score metrics exploitability metrics attack vector network attack complexity low privileges required none user interaction none scope unchanged impact metrics confidentiality impact none integrity impact none availability impact high for more information on scores click a href suggested fix type upgrade version origin a href release date fix resolution http proxy isopenpronvulnerability false ispackagebased true isdefaultbranch true packages istransitivedependency true dependencytree karma http proxy isminimumfixversionavailable true minimumfixversion http proxy basebranches vulnerabilityidentifier ws vulnerabilitydetails versions of http proxy prior to are vulnerable to denial of service an http request with a long body triggers an err http headers sent unhandled exception that crashes the proxy server this is only possible when the proxy server sets headers in the proxy request using the proxyreq setheader function vulnerabilityurl ,0969241688,20156394290.0,IssuesEvent,2022-02-09 16:50:18,rancher/qa-tasks,https://api.github.com/repos/rancher/qa-tasks,opened,2.6.3 Upgrade testing at scale ,area/scale-testing,"2.5.8-patch3 -> 2.6.3-patch1
970
971- [ ] Upgrade Rancher version
972- [ ] Upgrade local cluster k8s version
973- [ ] Upgrade downstream clusters k8s versions",1.0,"2.6.3 Upgrade testing at scale - 2.5.8-patch3 -> 2.6.3-patch1
974
975- [ ] Upgrade Rancher version
976- [ ] Upgrade local cluster k8s version
977- [ ] Upgrade downstream clusters k8s versions",0, upgrade testing at scale upgrade rancher version upgrade local cluster version upgrade downstream clusters versions,097812617,15014757707.0,IssuesEvent,2021-02-01 07:12:28,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[iOS] Occasionally getting 405 error on signout,Bug P1 Process: under observation iOS,"**Steps:**
9791. Login
9802. Navigate to my account
9813. Change any settings in my account eg. change passcode/password/disable settings
9824. Click on menu and signout
9835. Observe
984
985**Actual:** Occasionally getting 405 error on signout
986
987**Expected:** User should not get any unexpected error
988
989Note: step 3 is not mandatory to reproduce the issue, issue is occasionally happening
990
991Refer video
992
993
994https://user-images.githubusercontent.com/60386291/104805801-9ea43680-57f8-11eb-97e8-2fbbd9336bf5.MOV
995
996",1.0,"[iOS] Occasionally getting 405 error on signout - **Steps:**
9971. Login
9982. Navigate to my account
9993. Change any settings in my account eg. change passcode/password/disable settings
10004. Click on menu and signout
10015. Observe
1002
1003**Actual:** Occasionally getting 405 error on signout
1004
1005**Expected:** User should not get any unexpected error
1006
1007Note: step 3 is not mandatory to reproduce the issue, issue is occasionally happening
1008
1009Refer video
1010
1011
1012https://user-images.githubusercontent.com/60386291/104805801-9ea43680-57f8-11eb-97e8-2fbbd9336bf5.MOV
1013
1014",1, occasionally getting error on signout steps login navigate to my account change any settings in my account eg change passcode password disable settings click on menu and signout observe actual occasionally getting error on signout expected user should not get any unexpected error note step is not mandatory to reproduce the issue issue is occasionally happening refer video ,1101518699,24595609201.0,IssuesEvent,2022-10-14 08:04:08,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[FHIR] Json file > Time stamp should be local time ,Bug P2 Response datastore Process: Fixed Process: Tested QA Process: Tested dev,"AR: JSON file > Timestamp: Server time is getting displayed
1016ER: JSON file > Timestamp: It should display the local time for the following keys
10171. authored
10182. lastUpdated
1019
1020
1021
1022",3.0,"[FHIR] Json file > Time stamp should be local time - AR: JSON file > Timestamp: Server time is getting displayed
1023ER: JSON file > Timestamp: It should display the local time for the following keys
10241. authored
10252. lastUpdated
1026
1027
1028
1029",1, json file time stamp should be local time ar json file timestamp server time is getting displayed er json file timestamp it should display the local time for the following keys authored lastupdated ,1103015961,20175946018.0,IssuesEvent,2022-02-10 14:32:54,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,iOS 15 > UI Issues in Study activities screen,Bug P2 iOS UI Process: Fixed Process: Tested QA Process: Tested dev,"Steps:
1031
10321. Install iOS app with iOS 15+ compatible version
10332. Navigate across the screens
1034
1035Actual:
10361. Bottom navigation bar line separator is not displayed
10372. Dashboard > Bottom navigation icons are not highlighted
10383. Line seperator in Activities screen are not aligned properly
1039
1040Expected: UI should be as per design
1041
1042iOS Version: 15.0.1
1043Issue was not observed in < iOS 15 versions
1044
1045Refer attached screenshots for actual:
1046
1047
1048
1049Refer attached screenshot in older iOS versions for reference
1050
1051
1052
1053
1054",3.0,"iOS 15 > UI Issues in Study activities screen - Steps:
1055
10561. Install iOS app with iOS 15+ compatible version
10572. Navigate across the screens
1058
1059Actual:
10601. Bottom navigation bar line separator is not displayed
10612. Dashboard > Bottom navigation icons are not highlighted
10623. Line seperator in Activities screen are not aligned properly
1063
1064Expected: UI should be as per design
1065
1066iOS Version: 15.0.1
1067Issue was not observed in < iOS 15 versions
1068
1069Refer attached screenshots for actual:
1070
1071
1072
1073Refer attached screenshot in older iOS versions for reference
1074
1075
1076
1077
1078",1,ios ui issues in study activities screen steps install ios app with ios compatible version navigate across the screens actual bottom navigation bar line separator is not displayed dashboard bottom navigation icons are not highlighted line seperator in activities screen are not aligned properly expected ui should be as per design ios version issue was not observed in ios versions refer attached screenshots for actual refer attached screenshot in older ios versions for reference ,11079501654,14530643259.0,IssuesEvent,2020-12-14 19:34:03,ChainSafe/forest,https://api.github.com/repos/ChainSafe/forest,closed,Test Block Processing from Storage Miner: Perform state transitions for block received from Storage Miner,Priority: 3 - Medium Storage Miner,"When a block is received over RPC (from Storage Miner), the syncer must be notified so that the system can sync towards it.1080 1081Notes1082- We don't have a mechanism to notify the syncer as of now (we don't have access to the syncer from RPC). What is the best way to do this? A channel or a network event? This should be all there is to do.1083- A block from RPC or pubsub should be handled the same essentially (although there are peers to deal with on pubsub and track their heads, but that doesn't affect this issue)",1.0,"Test Block Processing from Storage Miner: Perform state transitions for block received from Storage Miner - When a block is received over RPC (from Storage Miner), the syncer must be notified so that the system can sync towards it.1084 1085Notes1086- We don't have a mechanism to notify the syncer as of now (we don't have access to the syncer from RPC). What is the best way to do this? A channel or a network event? This should be all there is to do.1087- A block from RPC or pubsub should be handled the same essentially (although there are peers to deal with on pubsub and track their heads, but that doesn't affect this issue)",0,test block processing from storage miner perform state transitions for block received from storage miner when a block is received over rpc from storage miner the syncer must be notified so that the system can sync towards it notes we don t have a mechanism to notify the syncer as of now we don t have access to the syncer from rpc what is the best way to do this a channel or a network event this should be all there is to do a block from rpc or pubsub should be handled the same essentially although there are peers to deal with on pubsub and track their heads but that doesn t affect this issue ,0108818622,24579561932.0,IssuesEvent,2022-10-13 14:41:28,GoogleCloudPlatform/fda-mystudies,https://api.github.com/repos/GoogleCloudPlatform/fda-mystudies,closed,[Consent API] [Android] [IOS] Data Sharing screen shot,Feature request Process: Fixed Process: Tested QA Process: Tested dev,"please add a `dataSharingScreenShot ` as a field and provide a data sharing screen shot details in `ConsentStatusBean `of ""/updateEligibilityConsentStatus"" API.
1089",3.0,"[Consent API] [Android] [IOS] Data Sharing screen shot - please add a `dataSharingScreenShot ` as a field and provide a data sharing screen shot details in `ConsentStatusBean `of ""/updateEligibilityConsentStatus"" API.
1090",1, data sharing screen shot please add a datasharingscreenshot as a field and provide a data sharing screen shot details in consentstatusbean of updateeligibilityconsentstatus api ,11091212793,23953009398.0,IssuesEvent,2022-09-12 13:03:43,mendts-workshop/MarcinKuder,https://api.github.com/repos/mendts-workshop/MarcinKuder,opened,mysql-connector-java-5.1.25.jar: 9 vulnerabilities (highest severity is: 8.5),security vulnerability,"<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>mysql-connector-java-5.1.25.jar</b></p></summary>1092 1093<p>MySQL JDBC Type 4 driver</p>1094<p>Library home page: <a href=""http://dev.mysql.com/doc/connector-j/en/"">http://dev.mysql.com/doc/connector-j/en/</a></p>1095<p>Path to dependency file: /pom.xml</p>1096<p>Path to vulnerable library: /epository/mysql/mysql-connector-java/5.1.25/mysql-connector-java-5.1.25.jar</p>1097<p>1098 1099 1100<p>Found in HEAD commit: <a href=""https://github.com/mendts-workshop/MarcinKuder/commit/316ad4ed4f8aad0802f46fc8f19b1625d6daa719"">316ad4ed4f8aad0802f46fc8f19b1625d6daa719</a></p></details>1101 1102## Vulnerabilities1103 1104| CVE | Severity | <img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS | Dependency | Type | Fixed in | Remediation Available |1105| ------------- | ------------- | ----- | ----- | ----- | --- | --- |1106| [CVE-2017-3523](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2017-3523) | <img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> High | 8.5 | mysql-connector-java-5.1.25.jar | Direct | 5.1.41 | ✅ |1107| [CVE-2022-21363](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2022-21363) | <img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> Medium | 6.6 | mysql-connector-java-5.1.25.jar | Direct | mysql:mysql-connector-java:8.0.28 | ✅ |1108| [CVE-2017-3586](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2017-3586) | <img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> Medium | 6.4 | mysql-connector-java-5.1.25.jar | Direct | 5.1.42 | ✅ |1109| [CVE-2020-2934](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-2934) | <img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> Medium | 5.0 | mysql-connector-java-5.1.25.jar | Direct | 5.1.49 | ✅ |1110| [CVE-2020-2875](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-2875) | <img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> Medium | 4.7 | mysql-connector-java-5.1.25.jar | Direct | 5.1.49 | ✅ |1111| [CVE-2019-2692](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2019-2692) | <img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> Medium | 4.5 | mysql-connector-java-5.1.25.jar | Direct | 5.1.48 | ✅ |1112| [CVE-2015-2575](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2015-2575) | <img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> Medium | 4.2 | mysql-connector-java-5.1.25.jar | Direct | 5.1.35 | ✅ |1113| [CVE-2017-3589](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2017-3589) | <img src='https://whitesource-resources.whitesourcesoftware.com/low_vul.png' width=19 height=20> Low | 3.3 | mysql-connector-java-5.1.25.jar | Direct | 5.1.42 | ✅ |1114| [CVE-2020-2933](https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-2933) | <img src='https://whitesource-resources.whitesourcesoftware.com/low_vul.png' width=19 height=20> Low | 2.2 | mysql-connector-java-5.1.25.jar | Direct | 5.1.49 | ✅ |1115 1116 1117## Details1118 1119<details>1120 1121<summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> CVE-2017-3523</summary>1122 1123 1124### Vulnerable Library - <b>mysql-connector-java-5.1.25.jar</b></p>1125 1126<p>MySQL JDBC Type 4 driver</p>1127<p>Library home page: <a href=""http://dev.mysql.com/doc/connector-j/en/"">http://dev.mysql.com/doc/connector-j/en/</a></p>1128<p>Path to dependency file: /pom.xml</p>1129<p>Path to vulnerable library: /epository/mysql/mysql-connector-java/5.1.25/mysql-connector-java-5.1.25.jar</p>1130<p>1131 1132Dependency Hierarchy:1133 - :x: **mysql-connector-java-5.1.25.jar** (Vulnerable Library)1134<p>Found in HEAD commit: <a href=""https://github.com/mendts-workshop/MarcinKuder/commit/316ad4ed4f8aad0802f46fc8f19b1625d6daa719"">316ad4ed4f8aad0802f46fc8f19b1625d6daa719</a></p>1135<p>Found in base branch: <b>master</b></p>1136</p>1137 1138<p></p>1139 1140### Vulnerability Details1141<p> 1142 1143Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).1144 1145<p>Publish Date: 2017-04-241146<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2017-3523>CVE-2017-3523</a></p>1147</p>1148 1149<p></p>1150 1151### CVSS 3 Score Details (<b>8.5</b>)1152<p>1153 1154Base Score Metrics:1155- Exploitability Metrics:1156 - Attack Vector: Network1157 - Attack Complexity: High1158 - Privileges Required: Low1159 - User Interaction: None1160 - Scope: Changed1161- Impact Metrics:1162 - Confidentiality Impact: High1163 - Integrity Impact: High1164 - Availability Impact: High1165</p>1166For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.1167</p>1168 1169<p></p>1170 1171### Suggested Fix1172<p>1173 1174<p>Type: Upgrade version</p>1175<p>Origin: <a href=""https://github.com/advisories/GHSA-2xxh-f8r3-hvvr"">https://github.com/advisories/GHSA-2xxh-f8r3-hvvr</a></p>1176<p>Release Date: 2017-04-24</p>1177<p>Fix Resolution: 5.1.41</p>1178 1179</p>1180 1181<p></p>1182 1183 1184:rescue_worker_helmet: Automatic Remediation is available for this issue1185</details><details>1186 1187<summary><img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> CVE-2022-21363</summary>1188 1189 1190### Vulnerable Library - <b>mysql-connector-java-5.1.25.jar</b></p>1191 1192<p>MySQL JDBC Type 4 driver</p>1193<p>Library home page: <a href=""http://dev.mysql.com/doc/connector-j/en/"">http://dev.mysql.com/doc/connector-j/en/</a></p>1194<p>Path to dependency file: /pom.xml</p>1195<p>Path to vulnerable library: /epository/mysql/mysql-connector-java/5.1.25/mysql-connector-java-5.1.25.jar</p>1196<p>1197 1198Dependency Hierarchy:1199 - :x: **mysql-connector-java-5.1.25.jar** (Vulnerable Library)1200<p>Found in HEAD commit: <a href=""https://github.com/mendts-workshop/MarcinKuder/commit/316ad4ed4f8aad0802f46fc8f19b1625d6daa719"">316ad4ed4f8aad0802f46fc8f19b1625d6daa719</a></p>