karths/binary_classification_train_automation
025
1Unnamed: 0,id,type,created_at,repo,repo_url,action,title,labels,body,index,text_combine,label,text,binary_label2147456,19522820647.0,IssuesEvent,2021-12-29 22:26:33,swagger-api/swagger-codegen,https://api.github.com/repos/swagger-api/swagger-codegen,opened,CVE-2020-36185 (High) detected in multiple libraries,security vulnerability,"## CVE-2020-36185 - High Severity Vulnerability3<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Libraries - <b>jackson-databind-2.7.8.jar</b>, <b>jackson-databind-2.8.9.jar</b>, <b>jackson-databind-2.6.4.jar</b>, <b>jackson-databind-2.8.8.jar</b>, <b>jackson-databind-2.4.5.jar</b></p></summary>4<p>5 6<details><summary><b>jackson-databind-2.7.8.jar</b></p></summary>7 8<p>General data-binding functionality for Jackson: works on core streaming API</p>9<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>10<p>Path to vulnerable library: /home/wss-scanner/.ivy2/cache/com.fasterxml.jackson.core/jackson-databind/bundles/jackson-databind-2.7.8.jar</p>11<p>12 13Dependency Hierarchy:14 - lagom-scaladsl-api_2.11-1.3.8.jar (Root Library)15 - lagom-api_2.11-1.3.8.jar16 - play_2.11-2.5.13.jar17 - :x: **jackson-databind-2.7.8.jar** (Vulnerable Library)18</details>19<details><summary><b>jackson-databind-2.8.9.jar</b></p></summary>20 21<p>General data-binding functionality for Jackson: works on core streaming API</p>22<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>23<p>Path to vulnerable library: /home/wss-scanner/.ivy2/cache/com.fasterxml.jackson.core/jackson-databind/bundles/jackson-databind-2.8.9.jar</p>24<p>25 26Dependency Hierarchy:27 - play-guice_2.12-2.6.3.jar (Root Library)28 - play_2.12-2.6.3.jar29 - :x: **jackson-databind-2.8.9.jar** (Vulnerable Library)30</details>31<details><summary><b>jackson-databind-2.6.4.jar</b></p></summary>32 33<p>General data-binding functionality for Jackson: works on core streaming API</p>34<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>35<p>Path to dependency file: /samples/client/petstore/java/jersey1/build.gradle</p>36<p>Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.6.4/f2abadd10891512268b16a1a1a6f81890f3e2976/jackson-databind-2.6.4.jar,/aches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.6.4/f2abadd10891512268b16a1a1a6f81890f3e2976/jackson-databind-2.6.4.jar</p>37<p>38 39Dependency Hierarchy:40 - :x: **jackson-databind-2.6.4.jar** (Vulnerable Library)41</details>42<details><summary><b>jackson-databind-2.8.8.jar</b></p></summary>43 44<p>General data-binding functionality for Jackson: works on core streaming API</p>45<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>46<p>Path to vulnerable library: /home/wss-scanner/.ivy2/cache/com.fasterxml.jackson.core/jackson-databind/bundles/jackson-databind-2.8.8.jar</p>47<p>48 49Dependency Hierarchy:50 - finch-circe_2.11-0.15.1.jar (Root Library)51 - circe-jackson28_2.11-0.8.0.jar52 - :x: **jackson-databind-2.8.8.jar** (Vulnerable Library)53</details>54<details><summary><b>jackson-databind-2.4.5.jar</b></p></summary>55 56<p>General data-binding functionality for Jackson: works on core streaming API</p>57<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>58<p>Path to dependency file: /samples/client/petstore/scala/build.gradle</p>59<p>Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.4.5/c69c0cb613128c69d84a6a0304ddb9fce82e8242/jackson-databind-2.4.5.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.4.5/c69c0cb613128c69d84a6a0304ddb9fce82e8242/jackson-databind-2.4.5.jar</p>60<p>61 62Dependency Hierarchy:63 - swagger-core-1.5.8.jar (Root Library)64 - :x: **jackson-databind-2.4.5.jar** (Vulnerable Library)65</details>66 67<p>Found in HEAD commit: <a href=""https://github.com/swagger-api/swagger-codegen/commit/4b7a8d7d7384aa6a27d6309c35ade0916edae7ed"">4b7a8d7d7384aa6a27d6309c35ade0916edae7ed</a></p>68<p>Found in base branch: <b>master</b></p>69</p>70</details>71<p></p>72<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> Vulnerability Details</summary>73<p> 74 75FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.76 77<p>Publish Date: 2021-01-0678<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-36185>CVE-2020-36185</a></p>79</p>80</details>81<p></p>82<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>8.1</b>)</summary>83<p>84 85Base Score Metrics:86- Exploitability Metrics:87 - Attack Vector: Network88 - Attack Complexity: High89 - Privileges Required: None90 - User Interaction: None91 - Scope: Unchanged92- Impact Metrics:93 - Confidentiality Impact: High94 - Integrity Impact: High95 - Availability Impact: High96</p>97For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.98</p>99</details>100<p></p>101<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>102<p>103 104<p>Type: Upgrade version</p>105<p>Origin: <a href=""https://github.com/FasterXML/jackson-databind/issues/2998"">https://github.com/FasterXML/jackson-databind/issues/2998</a></p>106<p>Release Date: 2021-01-06</p>107<p>Fix Resolution: com.fasterxml.jackson.core:jackson-databind:2.9.10.8</p>108 109</p>110</details>111<p></p>112 113<!-- <REMEDIATE>{""isOpenPROnVulnerability"":false,""isPackageBased"":true,""isDefaultBranch"":true,""packages"":[{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.7.8"",""packageFilePaths"":[null],""isTransitiveDependency"":true,""dependencyTree"":""com.lightbend.lagom:lagom-scaladsl-api_2.11:1.3.8;com.lightbend.lagom:lagom-api_2.11:1.3.8;com.typesafe.play:play_2.11:2.5.13;com.fasterxml.jackson.core:jackson-databind:2.7.8"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false},{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.8.9"",""packageFilePaths"":[null],""isTransitiveDependency"":true,""dependencyTree"":""com.typesafe.play:play-guice_2.12:2.6.3;com.typesafe.play:play_2.12:2.6.3;com.fasterxml.jackson.core:jackson-databind:2.8.9"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false},{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.6.4"",""packageFilePaths"":[""/samples/client/petstore/java/jersey1/build.gradle""],""isTransitiveDependency"":false,""dependencyTree"":""com.fasterxml.jackson.core:jackson-databind:2.6.4"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false},{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.8.8"",""packageFilePaths"":[null],""isTransitiveDependency"":true,""dependencyTree"":""com.github.finagle:finch-circe_2.11:0.15.1;io.circe:circe-jackson28_2.11:0.8.0;com.fasterxml.jackson.core:jackson-databind:2.8.8"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false},{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.4.5"",""packageFilePaths"":[""/samples/client/petstore/scala/build.gradle""],""isTransitiveDependency"":true,""dependencyTree"":""io.swagger:swagger-core:1.5.8;com.fasterxml.jackson.core:jackson-databind:2.4.5"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false}],""baseBranches"":[""master""],""vulnerabilityIdentifier"":""CVE-2020-36185"",""vulnerabilityDetails"":""FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource."",""vulnerabilityUrl"":""https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-36185"",""cvss3Severity"":""high"",""cvss3Score"":""8.1"",""cvss3Metrics"":{""A"":""High"",""AC"":""High"",""PR"":""None"",""S"":""Unchanged"",""C"":""High"",""UI"":""None"",""AV"":""Network"",""I"":""High""},""extraData"":{}}</REMEDIATE> -->",True,"CVE-2020-36185 (High) detected in multiple libraries - ## CVE-2020-36185 - High Severity Vulnerability114<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Libraries - <b>jackson-databind-2.7.8.jar</b>, <b>jackson-databind-2.8.9.jar</b>, <b>jackson-databind-2.6.4.jar</b>, <b>jackson-databind-2.8.8.jar</b>, <b>jackson-databind-2.4.5.jar</b></p></summary>115<p>116 117<details><summary><b>jackson-databind-2.7.8.jar</b></p></summary>118 119<p>General data-binding functionality for Jackson: works on core streaming API</p>120<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>121<p>Path to vulnerable library: /home/wss-scanner/.ivy2/cache/com.fasterxml.jackson.core/jackson-databind/bundles/jackson-databind-2.7.8.jar</p>122<p>123 124Dependency Hierarchy:125 - lagom-scaladsl-api_2.11-1.3.8.jar (Root Library)126 - lagom-api_2.11-1.3.8.jar127 - play_2.11-2.5.13.jar128 - :x: **jackson-databind-2.7.8.jar** (Vulnerable Library)129</details>130<details><summary><b>jackson-databind-2.8.9.jar</b></p></summary>131 132<p>General data-binding functionality for Jackson: works on core streaming API</p>133<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>134<p>Path to vulnerable library: /home/wss-scanner/.ivy2/cache/com.fasterxml.jackson.core/jackson-databind/bundles/jackson-databind-2.8.9.jar</p>135<p>136 137Dependency Hierarchy:138 - play-guice_2.12-2.6.3.jar (Root Library)139 - play_2.12-2.6.3.jar140 - :x: **jackson-databind-2.8.9.jar** (Vulnerable Library)141</details>142<details><summary><b>jackson-databind-2.6.4.jar</b></p></summary>143 144<p>General data-binding functionality for Jackson: works on core streaming API</p>145<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>146<p>Path to dependency file: /samples/client/petstore/java/jersey1/build.gradle</p>147<p>Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.6.4/f2abadd10891512268b16a1a1a6f81890f3e2976/jackson-databind-2.6.4.jar,/aches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.6.4/f2abadd10891512268b16a1a1a6f81890f3e2976/jackson-databind-2.6.4.jar</p>148<p>149 150Dependency Hierarchy:151 - :x: **jackson-databind-2.6.4.jar** (Vulnerable Library)152</details>153<details><summary><b>jackson-databind-2.8.8.jar</b></p></summary>154 155<p>General data-binding functionality for Jackson: works on core streaming API</p>156<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>157<p>Path to vulnerable library: /home/wss-scanner/.ivy2/cache/com.fasterxml.jackson.core/jackson-databind/bundles/jackson-databind-2.8.8.jar</p>158<p>159 160Dependency Hierarchy:161 - finch-circe_2.11-0.15.1.jar (Root Library)162 - circe-jackson28_2.11-0.8.0.jar163 - :x: **jackson-databind-2.8.8.jar** (Vulnerable Library)164</details>165<details><summary><b>jackson-databind-2.4.5.jar</b></p></summary>166 167<p>General data-binding functionality for Jackson: works on core streaming API</p>168<p>Library home page: <a href=""http://github.com/FasterXML/jackson"">http://github.com/FasterXML/jackson</a></p>169<p>Path to dependency file: /samples/client/petstore/scala/build.gradle</p>170<p>Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.4.5/c69c0cb613128c69d84a6a0304ddb9fce82e8242/jackson-databind-2.4.5.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-databind/2.4.5/c69c0cb613128c69d84a6a0304ddb9fce82e8242/jackson-databind-2.4.5.jar</p>171<p>172 173Dependency Hierarchy:174 - swagger-core-1.5.8.jar (Root Library)175 - :x: **jackson-databind-2.4.5.jar** (Vulnerable Library)176</details>177 178<p>Found in HEAD commit: <a href=""https://github.com/swagger-api/swagger-codegen/commit/4b7a8d7d7384aa6a27d6309c35ade0916edae7ed"">4b7a8d7d7384aa6a27d6309c35ade0916edae7ed</a></p>179<p>Found in base branch: <b>master</b></p>180</p>181</details>182<p></p>183<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> Vulnerability Details</summary>184<p> 185 186FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.187 188<p>Publish Date: 2021-01-06189<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-36185>CVE-2020-36185</a></p>190</p>191</details>192<p></p>193<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>8.1</b>)</summary>194<p>195 196Base Score Metrics:197- Exploitability Metrics:198 - Attack Vector: Network199 - Attack Complexity: High200 - Privileges Required: None201 - User Interaction: None202 - Scope: Unchanged203- Impact Metrics:204 - Confidentiality Impact: High205 - Integrity Impact: High206 - Availability Impact: High207</p>208For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.209</p>210</details>211<p></p>212<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>213<p>214 215<p>Type: Upgrade version</p>216<p>Origin: <a href=""https://github.com/FasterXML/jackson-databind/issues/2998"">https://github.com/FasterXML/jackson-databind/issues/2998</a></p>217<p>Release Date: 2021-01-06</p>218<p>Fix Resolution: com.fasterxml.jackson.core:jackson-databind:2.9.10.8</p>219 220</p>221</details>222<p></p>223 224<!-- <REMEDIATE>{""isOpenPROnVulnerability"":false,""isPackageBased"":true,""isDefaultBranch"":true,""packages"":[{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.7.8"",""packageFilePaths"":[null],""isTransitiveDependency"":true,""dependencyTree"":""com.lightbend.lagom:lagom-scaladsl-api_2.11:1.3.8;com.lightbend.lagom:lagom-api_2.11:1.3.8;com.typesafe.play:play_2.11:2.5.13;com.fasterxml.jackson.core:jackson-databind:2.7.8"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false},{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.8.9"",""packageFilePaths"":[null],""isTransitiveDependency"":true,""dependencyTree"":""com.typesafe.play:play-guice_2.12:2.6.3;com.typesafe.play:play_2.12:2.6.3;com.fasterxml.jackson.core:jackson-databind:2.8.9"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false},{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.6.4"",""packageFilePaths"":[""/samples/client/petstore/java/jersey1/build.gradle""],""isTransitiveDependency"":false,""dependencyTree"":""com.fasterxml.jackson.core:jackson-databind:2.6.4"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false},{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.8.8"",""packageFilePaths"":[null],""isTransitiveDependency"":true,""dependencyTree"":""com.github.finagle:finch-circe_2.11:0.15.1;io.circe:circe-jackson28_2.11:0.8.0;com.fasterxml.jackson.core:jackson-databind:2.8.8"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false},{""packageType"":""Java"",""groupId"":""com.fasterxml.jackson.core"",""packageName"":""jackson-databind"",""packageVersion"":""2.4.5"",""packageFilePaths"":[""/samples/client/petstore/scala/build.gradle""],""isTransitiveDependency"":true,""dependencyTree"":""io.swagger:swagger-core:1.5.8;com.fasterxml.jackson.core:jackson-databind:2.4.5"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""com.fasterxml.jackson.core:jackson-databind:2.9.10.8"",""isBinary"":false}],""baseBranches"":[""master""],""vulnerabilityIdentifier"":""CVE-2020-36185"",""vulnerabilityDetails"":""FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource."",""vulnerabilityUrl"":""https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-36185"",""cvss3Severity"":""high"",""cvss3Score"":""8.1"",""cvss3Metrics"":{""A"":""High"",""AC"":""High"",""PR"":""None"",""S"":""Unchanged"",""C"":""High"",""UI"":""None"",""AV"":""Network"",""I"":""High""},""extraData"":{}}</REMEDIATE> -->",0,cve high detected in multiple libraries cve high severity vulnerability vulnerable libraries jackson databind jar jackson databind jar jackson databind jar jackson databind jar jackson databind jar jackson databind jar general data binding functionality for jackson works on core streaming api library home page a href path to vulnerable library home wss scanner cache com fasterxml jackson core jackson databind bundles jackson databind jar dependency hierarchy lagom scaladsl api jar root library lagom api jar play jar x jackson databind jar vulnerable library jackson databind jar general data binding functionality for jackson works on core streaming api library home page a href path to vulnerable library home wss scanner cache com fasterxml jackson core jackson databind bundles jackson databind jar dependency hierarchy play guice jar root library play jar x jackson databind jar vulnerable library jackson databind jar general data binding functionality for jackson works on core streaming api library home page a href path to dependency file samples client petstore java build gradle path to vulnerable library home wss scanner gradle caches modules files com fasterxml jackson core jackson databind jackson databind jar aches modules files com fasterxml jackson core jackson databind jackson databind jar dependency hierarchy x jackson databind jar vulnerable library jackson databind jar general data binding functionality for jackson works on core streaming api library home page a href path to vulnerable library home wss scanner cache com fasterxml jackson core jackson databind bundles jackson databind jar dependency hierarchy finch circe jar root library circe jar x jackson databind jar vulnerable library jackson databind jar general data binding functionality for jackson works on core streaming api library home page a href path to dependency file samples client petstore scala build gradle path to vulnerable library home wss scanner gradle caches modules files com fasterxml jackson core jackson databind jackson databind jar home wss scanner gradle caches modules files com fasterxml jackson core jackson databind jackson databind jar dependency hierarchy swagger core jar root library x jackson databind jar vulnerable library found in head commit a href found in base branch master vulnerability details fasterxml jackson databind x before mishandles the interaction between serialization gadgets and typing related to org apache tomcat dbcp datasources sharedpooldatasource publish date url a href cvss score details base score metrics exploitability metrics attack vector network attack complexity high privileges required none user interaction none scope unchanged impact metrics confidentiality impact high integrity impact high availability impact high for more information on scores click a href suggested fix type upgrade version origin a href release date fix resolution com fasterxml jackson core jackson databind isopenpronvulnerability false ispackagebased true isdefaultbranch true packages istransitivedependency true dependencytree com lightbend lagom lagom scaladsl api com lightbend lagom lagom api com typesafe play play com fasterxml jackson core jackson databind isminimumfixversionavailable true minimumfixversion com fasterxml jackson core jackson databind isbinary false packagetype java groupid com fasterxml jackson core packagename jackson databind packageversion packagefilepaths istransitivedependency true dependencytree com typesafe play play guice com typesafe play play com fasterxml jackson core jackson databind isminimumfixversionavailable true minimumfixversion com fasterxml jackson core jackson databind isbinary false packagetype java groupid com fasterxml jackson core packagename jackson databind packageversion packagefilepaths istransitivedependency false dependencytree com fasterxml jackson core jackson databind isminimumfixversionavailable true minimumfixversion com fasterxml jackson core jackson databind isbinary false packagetype java groupid com fasterxml jackson core packagename jackson databind packageversion packagefilepaths istransitivedependency true dependencytree com github finagle finch circe io circe circe com fasterxml jackson core jackson databind isminimumfixversionavailable true minimumfixversion com fasterxml jackson core jackson databind isbinary false packagetype java groupid com fasterxml jackson core packagename jackson databind packageversion packagefilepaths istransitivedependency true dependencytree io swagger swagger core com fasterxml jackson core jackson databind isminimumfixversionavailable true minimumfixversion com fasterxml jackson core jackson databind isbinary false basebranches vulnerabilityidentifier cve vulnerabilitydetails fasterxml jackson databind x before mishandles the interaction between serialization gadgets and typing related to org apache tomcat dbcp datasources sharedpooldatasource vulnerabilityurl ,022536534,15022780078.0,IssuesEvent,2021-02-01 17:22:14,hashicorp/terraform-provider-aws,https://api.github.com/repos/hashicorp/terraform-provider-aws,closed,Getting unknown block type advanced_backup setting ,service/backup,"I am using terraform v0.12.14 226I am getting unknown block type **advanced_backup_setting** while using it in my tf code. Can someone please help. I have verified it is using provider.aws version 3.26227 228resource ""aws_backup_plan"" ""test_backup"" {229 name = ""test_backup_plan""230 231 rule {232 rule_name = ""test_backup_rule""233 target_vault_name = aws_backup_vault.test.name234 schedule = ""cron(0 16 * * ? *)""235 }236 237 advanced_backup_setting {238 backup_options = {239 WindowsVSS = ""enabled""240 }241 resource_type = ""EC2""242 }243}244",1.0,"Getting unknown block type advanced_backup setting - I am using terraform v0.12.14 245I am getting unknown block type **advanced_backup_setting** while using it in my tf code. Can someone please help. I have verified it is using provider.aws version 3.26246 247resource ""aws_backup_plan"" ""test_backup"" {248 name = ""test_backup_plan""249 250 rule {251 rule_name = ""test_backup_rule""252 target_vault_name = aws_backup_vault.test.name253 schedule = ""cron(0 16 * * ? *)""254 }255 256 advanced_backup_setting {257 backup_options = {258 WindowsVSS = ""enabled""259 }260 resource_type = ""EC2""261 }262}263",0,getting unknown block type advanced backup setting i am using terraform i am getting unknown block type advanced backup setting while using it in my tf code can someone please help i have verified it is using provider aws version resource aws backup plan test backup name test backup plan rule rule name test backup rule target vault name aws backup vault test name schedule cron advanced backup setting backup options windowsvss enabled resource type ,026499693,8708527890.0,IssuesEvent,2018-12-06 11:10:15,KratosMultiphysics/Kratos,https://api.github.com/repos/KratosMultiphysics/Kratos,closed,[Ttesting][Adjoint] Missing header here (with the license and the author),Kratos Core Licencing Testing,"https://github.com/KratosMultiphysics/Kratos/blob/c5b413682acd83040b72e26ab64eab21139bfac6/kratos/tests/strategies/schemes/test_residual_based_adjoint_bossak_scheme.cpp#L1265 266Besides, wait until the cpp tests are moved to a common folder",1.0,"[Ttesting][Adjoint] Missing header here (with the license and the author) - https://github.com/KratosMultiphysics/Kratos/blob/c5b413682acd83040b72e26ab64eab21139bfac6/kratos/tests/strategies/schemes/test_residual_based_adjoint_bossak_scheme.cpp#L1267 268Besides, wait until the cpp tests are moved to a common folder",0, missing header here with the license and the author besides wait until the cpp tests are moved to a common folder,02695880,21553443207.0,IssuesEvent,2022-04-30 02:43:07,o3de/o3de,https://api.github.com/repos/o3de/o3de,opened,AR Bug Report - Test AutomatedTesting::MultiplayerTests_Main failed,kind/bug needs-triage kind/automation,"**Describe the bug**270 271`AutomatedTesting::MultiplayerTests_Main.main::TEST_RUN` failed while running AR 272 273**Failed Jenkins Job Information:**274 275platform linux -- Python 3.7.12, pytest-5.3.2, py-1.11.0, pluggy-0.13.1 -- /data/workspace/o3de/python/runtime/python-3.7.12-rev2-linux/python/bin/python276 277```278[2022-04-29T10:46:42.179Z] E Failed: Test test_Multiplayer_AutoComponent_NetworkInput:279[2022-04-29T10:46:42.179Z] E Test FAILED280[2022-04-29T10:46:42.179Z] E ------------281[2022-04-29T10:46:42.179Z] E | Output |282[2022-04-29T10:46:42.179Z] E ------------283[2022-04-29T10:46:42.179Z] E Starting test Multiplayer_AutoComponent_NetworkInput...284[2022-04-29T10:46:42.179Z] E Test Multiplayer_AutoComponent_NetworkInput finished.285[2022-04-29T10:46:42.179Z] E Report:286[2022-04-29T10:46:42.179Z] E [SUCCESS] Success: Unexpected line not found: LaunchEditorServer failed! The ServerLauncher binary is missing!287[2022-04-29T10:46:42.179Z] E [SUCCESS] Success: Found expected line: Editor has connected to the editor-server.288[2022-04-29T10:46:42.179Z] E [SUCCESS] Success: Found expected line: Editor is sending the editor-server the level data packet.289[2022-04-29T10:46:42.179Z] E [FAILED ] Failure: Failed to find expected line: Logger: Editor Server completed receiving the editor's level assets, responding to Editor...290[2022-04-29T10:46:42.179Z] E EXCEPTION raised:291[2022-04-29T10:46:42.179Z] E Traceback (most recent call last):292[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 305, in start_test293[2022-04-29T10:46:42.179Z] E test_function()294[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/Multiplayer/tests/Multiplayer_AutoComponent_NetworkInput.py"", line 57, in Multiplayer_AutoComponent_NetworkInput295[2022-04-29T10:46:42.179Z] E helper.multiplayer_enter_game_mode(Tests.enter_game_mode)296[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 178, in multiplayer_enter_game_mode297[2022-04-29T10:46:42.179Z] E TestHelper.succeed_if_log_line_found(""EditorServer"", ""Logger: Editor Server completed receiving the editor's level assets, responding to Editor..."", section_tracer.prints, 5.0)298[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 138, in succeed_if_log_line_found299[2022-04-29T10:46:42.179Z] E Report.critical_result((""Found expected line: "" + line, ""Failed to find expected line: "" + line), TestHelper.find_line(window, line, print_infos))300[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 410, in critical_result301[2022-04-29T10:46:42.179Z] E TestHelper.fail_fast(fast_fail_message)302[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 213, in fail_fast303[2022-04-29T10:46:42.179Z] E raise FailFast()304[2022-04-29T10:46:42.179Z] E editor_python_test_tools.utils.FailFast305[2022-04-29T10:46:42.179Z] E Test result: FAILURE306```307 308**Attachments**309 310[log.txt](https://github.com/o3de/o3de/files/8595521/log.txt)311 312",1.0,"AR Bug Report - Test AutomatedTesting::MultiplayerTests_Main failed - **Describe the bug**313 314`AutomatedTesting::MultiplayerTests_Main.main::TEST_RUN` failed while running AR 315 316**Failed Jenkins Job Information:**317 318platform linux -- Python 3.7.12, pytest-5.3.2, py-1.11.0, pluggy-0.13.1 -- /data/workspace/o3de/python/runtime/python-3.7.12-rev2-linux/python/bin/python319 320```321[2022-04-29T10:46:42.179Z] E Failed: Test test_Multiplayer_AutoComponent_NetworkInput:322[2022-04-29T10:46:42.179Z] E Test FAILED323[2022-04-29T10:46:42.179Z] E ------------324[2022-04-29T10:46:42.179Z] E | Output |325[2022-04-29T10:46:42.179Z] E ------------326[2022-04-29T10:46:42.179Z] E Starting test Multiplayer_AutoComponent_NetworkInput...327[2022-04-29T10:46:42.179Z] E Test Multiplayer_AutoComponent_NetworkInput finished.328[2022-04-29T10:46:42.179Z] E Report:329[2022-04-29T10:46:42.179Z] E [SUCCESS] Success: Unexpected line not found: LaunchEditorServer failed! The ServerLauncher binary is missing!330[2022-04-29T10:46:42.179Z] E [SUCCESS] Success: Found expected line: Editor has connected to the editor-server.331[2022-04-29T10:46:42.179Z] E [SUCCESS] Success: Found expected line: Editor is sending the editor-server the level data packet.332[2022-04-29T10:46:42.179Z] E [FAILED ] Failure: Failed to find expected line: Logger: Editor Server completed receiving the editor's level assets, responding to Editor...333[2022-04-29T10:46:42.179Z] E EXCEPTION raised:334[2022-04-29T10:46:42.179Z] E Traceback (most recent call last):335[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 305, in start_test336[2022-04-29T10:46:42.179Z] E test_function()337[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/Multiplayer/tests/Multiplayer_AutoComponent_NetworkInput.py"", line 57, in Multiplayer_AutoComponent_NetworkInput338[2022-04-29T10:46:42.179Z] E helper.multiplayer_enter_game_mode(Tests.enter_game_mode)339[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 178, in multiplayer_enter_game_mode340[2022-04-29T10:46:42.179Z] E TestHelper.succeed_if_log_line_found(""EditorServer"", ""Logger: Editor Server completed receiving the editor's level assets, responding to Editor..."", section_tracer.prints, 5.0)341[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 138, in succeed_if_log_line_found342[2022-04-29T10:46:42.179Z] E Report.critical_result((""Found expected line: "" + line, ""Failed to find expected line: "" + line), TestHelper.find_line(window, line, print_infos))343[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 410, in critical_result344[2022-04-29T10:46:42.179Z] E TestHelper.fail_fast(fast_fail_message)345[2022-04-29T10:46:42.179Z] E File ""/data/workspace/o3de/AutomatedTesting/Gem/PythonTests/EditorPythonTestTools/editor_python_test_tools/utils.py"", line 213, in fail_fast346[2022-04-29T10:46:42.179Z] E raise FailFast()347[2022-04-29T10:46:42.179Z] E editor_python_test_tools.utils.FailFast348[2022-04-29T10:46:42.179Z] E Test result: FAILURE349```350 351**Attachments**352 353[log.txt](https://github.com/o3de/o3de/files/8595521/log.txt)354 355",1,ar bug report test automatedtesting multiplayertests main failed describe the bug automatedtesting multiplayertests main main test run failed while running ar failed jenkins job information platform linux python pytest py pluggy data workspace python runtime python linux python bin python e failed test test multiplayer autocomponent networkinput e test failed e e output e e starting test multiplayer autocomponent networkinput e test multiplayer autocomponent networkinput finished e report e success unexpected line not found launcheditorserver failed the serverlauncher binary is missing e success found expected line editor has connected to the editor server e success found expected line editor is sending the editor server the level data packet e failure failed to find expected line logger editor server completed receiving the editor s level assets responding to editor e exception raised e traceback most recent call last e file data workspace automatedtesting gem pythontests editorpythontesttools editor python test tools utils py line in start test e test function e file data workspace automatedtesting gem pythontests multiplayer tests multiplayer autocomponent networkinput py line in multiplayer autocomponent networkinput e helper multiplayer enter game mode tests enter game mode e file data workspace automatedtesting gem pythontests editorpythontesttools editor python test tools utils py line in multiplayer enter game mode e testhelper succeed if log line found editorserver logger editor server completed receiving the editor s level assets responding to editor section tracer prints e file data workspace automatedtesting gem pythontests editorpythontesttools editor python test tools utils py line in succeed if log line found e report critical result found expected line line failed to find expected line line testhelper find line window line print infos e file data workspace automatedtesting gem pythontests editorpythontesttools editor python test tools utils py line in critical result e testhelper fail fast fast fail message e file data workspace automatedtesting gem pythontests editorpythontesttools editor python test tools utils py line in fail fast e raise failfast e editor python test tools utils failfast e test result failure attachments ,13569271,27832546230.0,IssuesEvent,2023-03-20 06:46:44,pingcap/tiflow,https://api.github.com/repos/pingcap/tiflow,closed,Table sink close stucks and CDC changefeed not advance ,type/bug severity/critical found/automation area/ticdc affects-6.5 affects-6.6,"### What did you do?357 3581. create mysql changefeed3592. Run workload tpcc prepare3603. scale out tikv from 3 to 73614. scale in cdc from 3 to 1 node3625. tpcc run, and at the same time, scale out cdc from 3 to 6, and scale tikv in from 7 to 3.3636. wait checkpoint advance364 365### What did you expect to see?366 367changefeed advances368 369### What did you see instead?370 371changefeed not advances372 373374 375 376377 378 379### Versions of the cluster380 381cdc version:382[""Welcome to Change Data Capture (CDC)""] [release-version=v6.7.0-alpha] [git-hash=04f7e22aaa07dfedff853fe9b7a08675bbbf0fe1] [git-branch=heads/refs/tags/v6.7.0-alpha] [utc-build-time=""2023-03-11 11:32:23""] [go-version=""go version go1.20.2 linux/amd64""] [failpoint-build=false]383",1.0,"Table sink close stucks and CDC changefeed not advance - ### What did you do?384 3851. create mysql changefeed3862. Run workload tpcc prepare3873. scale out tikv from 3 to 73884. scale in cdc from 3 to 1 node3895. tpcc run, and at the same time, scale out cdc from 3 to 6, and scale tikv in from 7 to 3.3906. wait checkpoint advance391 392### What did you expect to see?393 394changefeed advances395 396### What did you see instead?397 398changefeed not advances399 400401 402 403404 405 406### Versions of the cluster407 408cdc version:409[""Welcome to Change Data Capture (CDC)""] [release-version=v6.7.0-alpha] [git-hash=04f7e22aaa07dfedff853fe9b7a08675bbbf0fe1] [git-branch=heads/refs/tags/v6.7.0-alpha] [utc-build-time=""2023-03-11 11:32:23""] [go-version=""go version go1.20.2 linux/amd64""] [failpoint-build=false]410",1,table sink close stucks and cdc changefeed not advance what did you do create mysql changefeed run workload tpcc prepare scale out tikv from to scale in cdc from to node tpcc run and at the same time scale out cdc from to and scale tikv in from to wait checkpoint advance what did you expect to see changefeed advances what did you see instead changefeed not advances versions of the cluster cdc version ,14111269,9815410570.0,IssuesEvent,2019-06-13 12:35:58,elastic/apm-integration-testing,https://api.github.com/repos/elastic/apm-integration-testing,closed,Support for multibranch pipeline,[zube]: In Review automation,"As an effort to standardise CI/CD work across the Observability teams, alongside using the JJBB framework, we want to add support for Jenkins' multibranch pipelines.",1.0,"Support for multibranch pipeline - As an effort to standardise CI/CD work across the Observability teams, alongside using the JJBB framework, we want to add support for Jenkins' multibranch pipelines.",1,support for multibranch pipeline as an effort to standardise ci cd work across the observability teams alongside using the jjbb framework we want to add support for jenkins multibranch pipelines ,14127468,24944522212.0,IssuesEvent,2022-10-31 22:13:21,ericcornelissen/webmangler,https://api.github.com/repos/ericcornelissen/webmangler,closed,Address use of deprecated GitHub Actions command `set-output`,automation,"# Task413 414## Description415 416All GitHub Actions workflows should be updated to not rely on `set-output` or `save-state` which, per the following warnings that may be seen on current workflow runs (example), have been deprecated:417 418> The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/419 420At the time of writing, this warning can be seen on runs of the following workflows of this project:421 422- [`code-analysis.yml`](https://github.com/ericcornelissen/webmangler/blob/7999a8bd1c4e653740f78715b3573d04fc39fa4e/.github/workflows/code-analysis.yml)423- [`code-checks.yml`](https://github.com/ericcornelissen/webmangler/blob/7999a8bd1c4e653740f78715b3573d04fc39fa4e/.github/workflows/code-checks.yml)424 425### `code-analysis.yml`426 427This is due to the use of `@actions/core@v1.9.1` in v2.1.27 of the CodeQL Action. This is already fixed in the CodeQL Action, but not yet released. This will be addressed automatically by the regular Renovate Pull Requests.428 429### `code-checks.yml`430 431This is due to the use of `echo ""::set-output name=xxx::yyy""` in embedded scripts in the [""Determine jobs"" job](https://github.com/ericcornelissen/webmangler/blob/7999a8bd1c4e653740f78715b3573d04fc39fa4e/.github/workflows/code-checks.yml#L11-L107). This must be addressed manually.432 433#### Suggested solution434 435Based on https://github.com/github/codeql-action/compare/v2.1.27...v2.1.28 it looks like changing the workflow as follows _should_ work:436 437```diff438- echo ""::set-output name=xxx::$yyy""439+ echo ""xxx=$yyy"" >> $GITHUB_OUTPUT440```441 442## Related443 444- #152445- #392446- #399 447- #412",1.0,"Address use of deprecated GitHub Actions command `set-output` - # Task448 449## Description450 451All GitHub Actions workflows should be updated to not rely on `set-output` or `save-state` which, per the following warnings that may be seen on current workflow runs (example), have been deprecated:452 453> The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/454 455At the time of writing, this warning can be seen on runs of the following workflows of this project:456 457- [`code-analysis.yml`](https://github.com/ericcornelissen/webmangler/blob/7999a8bd1c4e653740f78715b3573d04fc39fa4e/.github/workflows/code-analysis.yml)458- [`code-checks.yml`](https://github.com/ericcornelissen/webmangler/blob/7999a8bd1c4e653740f78715b3573d04fc39fa4e/.github/workflows/code-checks.yml)459 460### `code-analysis.yml`461 462This is due to the use of `@actions/core@v1.9.1` in v2.1.27 of the CodeQL Action. This is already fixed in the CodeQL Action, but not yet released. This will be addressed automatically by the regular Renovate Pull Requests.463 464### `code-checks.yml`465 466This is due to the use of `echo ""::set-output name=xxx::yyy""` in embedded scripts in the [""Determine jobs"" job](https://github.com/ericcornelissen/webmangler/blob/7999a8bd1c4e653740f78715b3573d04fc39fa4e/.github/workflows/code-checks.yml#L11-L107). This must be addressed manually.467 468#### Suggested solution469 470Based on https://github.com/github/codeql-action/compare/v2.1.27...v2.1.28 it looks like changing the workflow as follows _should_ work:471 472```diff473- echo ""::set-output name=xxx::$yyy""474+ echo ""xxx=$yyy"" >> $GITHUB_OUTPUT475```476 477## Related478 479- #152480- #392481- #399 482- #412",1,address use of deprecated github actions command set output task description all github actions workflows should be updated to not rely on set output or save state which per the following warnings that may be seen on current workflow runs example have been deprecated the set output command is deprecated and will be disabled soon please upgrade to using environment files for more information see at the time of writing this warning can be seen on runs of the following workflows of this project code analysis yml this is due to the use of actions core in of the codeql action this is already fixed in the codeql action but not yet released this will be addressed automatically by the regular renovate pull requests code checks yml this is due to the use of echo set output name xxx yyy in embedded scripts in the this must be addressed manually suggested solution based on it looks like changing the workflow as follows should work diff echo set output name xxx yyy echo xxx yyy github output related ,14837388,24767699872.0,IssuesEvent,2022-10-22 18:48:26,surge-synthesizer/surge,https://api.github.com/repos/surge-synthesizer/surge,closed,Live 11 Parameter Feedback,Host Specific Host Automation Bug Report,"XT in Live 11 seems to have slider drag events fight with the automation recording484 485Just you know, start live 11 and drag a slider and it wobbles486 487Sometimes this manifests itself as slider resets to 0 suddenly in some sort of cascade488 489This is clearly something in the notify / return value loop in live while dragging and begin/end not suppressing returns or some such but we need to debug it for our next release.",1.0,"Live 11 Parameter Feedback - XT in Live 11 seems to have slider drag events fight with the automation recording490 491Just you know, start live 11 and drag a slider and it wobbles492 493Sometimes this manifests itself as slider resets to 0 suddenly in some sort of cascade494 495This is clearly something in the notify / return value loop in live while dragging and begin/end not suppressing returns or some such but we need to debug it for our next release.",1,live parameter feedback xt in live seems to have slider drag events fight with the automation recording just you know start live and drag a slider and it wobbles sometimes this manifests itself as slider resets to suddenly in some sort of cascade this is clearly something in the notify return value loop in live while dragging and begin end not suppressing returns or some such but we need to debug it for our next release ,14969936,30783065865.0,IssuesEvent,2023-07-31 11:24:36,deinstapel/eks-rolling-update,https://api.github.com/repos/deinstapel/eks-rolling-update,opened,GitHub actions from forks will currently fail,automation,"Creating a PR from a fork will currently fail in github actions. This is due to the `github.actor` being unauthorized to push to the container registry. As we manually approve PRs as safe before running github actions, we should use a dedicated bot account with PAT instead.",1.0,"GitHub actions from forks will currently fail - Creating a PR from a fork will currently fail in github actions. This is due to the `github.actor` being unauthorized to push to the container registry. As we manually approve PRs as safe before running github actions, we should use a dedicated bot account with PAT instead.",1,github actions from forks will currently fail creating a pr from a fork will currently fail in github actions this is due to the github actor being unauthorized to push to the container registry as we manually approve prs as safe before running github actions we should use a dedicated bot account with pat instead ,14971488,10197698115.0,IssuesEvent,2019-08-13 01:39:25,askmench/mench-web-app,https://api.github.com/repos/askmench/mench-web-app,closed,Enable Users to Clear Action Plan Progression Links,Bot/Chat-Automation Inputs/Forms,So they can reset their mistakes and re-take all or parts of their Action Plan intentions.,1.0,Enable Users to Clear Action Plan Progression Links - So they can reset their mistakes and re-take all or parts of their Action Plan intentions.,1,enable users to clear action plan progression links so they can reset their mistakes and re take all or parts of their action plan intentions ,14985829,21333609143.0,IssuesEvent,2022-04-18 11:51:45,red-hat-storage/ocs-ci,https://api.github.com/repos/red-hat-storage/ocs-ci,opened,Wait for project selection is namespace drop-down on OCP console,bug ui_automation,"Issue seen with Run `1649886578`499Also take screenshots on important pages.",1.0,"Wait for project selection is namespace drop-down on OCP console - Issue seen with Run `1649886578`500Also take screenshots on important pages.",1,wait for project selection is namespace drop down on ocp console issue seen with run also take screenshots on important pages ,150148593,10263500707.0,IssuesEvent,2019-08-22 14:29:11,OrifInformatique/gestion_questionnaires,https://api.github.com/repos/OrifInformatique/gestion_questionnaires,closed,Charger uniquement les modรจles les plus utilisรฉs au lancement,code enhancement,"Dans la plupart des controlleurs, la fonction `__construct` charge tous les modรจles utilisรฉs, mรชme s'ils ne sont utilisรฉs qu'une seule fois dans le controlleur.502 503Il serait probablement prรฉfรฉrable de ne charger que ceux qui sont utilisรฉs souvent dans `__construct` et les autres dans les fonctions oรน ils sont utilisรฉs.",1.0,"Charger uniquement les modรจles les plus utilisรฉs au lancement - Dans la plupart des controlleurs, la fonction `__construct` charge tous les modรจles utilisรฉs, mรชme s'ils ne sont utilisรฉs qu'une seule fois dans le controlleur.504 505Il serait probablement prรฉfรฉrable de ne charger que ceux qui sont utilisรฉs souvent dans `__construct` et les autres dans les fonctions oรน ils sont utilisรฉs.",0,charger uniquement les modรจles les plus utilisรฉs au lancement dans la plupart des controlleurs la fonction construct charge tous les modรจles utilisรฉs mรชme s ils ne sont utilisรฉs qu une seule fois dans le controlleur il serait probablement prรฉfรฉrable de ne charger que ceux qui sont utilisรฉs souvent dans construct et les autres dans les fonctions oรน ils sont utilisรฉs ,0506336240,24490353024.0,IssuesEvent,2022-10-10 00:24:39,datajoint/datajoint-elements,https://api.github.com/repos/datajoint/datajoint-elements,closed,Add documentation on release process,documentation,"- Add versions of acquisition and analysis packages to release notes.507- Add this documentation within the `Management` section.",1.0,"Add documentation on release process - - Add versions of acquisition and analysis packages to release notes.508- Add this documentation within the `Management` section.",0,add documentation on release process add versions of acquisition and analysis packages to release notes add this documentation within the management section ,0509392353,26935956376.0,IssuesEvent,2023-02-07 20:40:33,onflow/flow-cli,https://api.github.com/repos/onflow/flow-cli,closed,Include a clarification about how to provide the arguments of a transaction like a json file,Documentation,"### Issue To Be Solved510How to pass a json file for providing the arguments of a transaction using flow-cli is not documented511 512### Suggest A Solution513Update the [docs](https://developers.flow.com/tools/flow-cli/send-signed-transactions) with clear instructions about how to do it 514`flow transactions send {filename} --args-json ""$(cat myfile.json)""` || `flow transactions send {filename}""$(wget -O- -q https://raw.githubusercontent.com/onflow/some-flow-repo/some-commit-hash-or-tag/path-to/arguments.json)"" `",1.0,"Include a clarification about how to provide the arguments of a transaction like a json file - ### Issue To Be Solved515How to pass a json file for providing the arguments of a transaction using flow-cli is not documented516 517### Suggest A Solution518Update the [docs](https://developers.flow.com/tools/flow-cli/send-signed-transactions) with clear instructions about how to do it 519`flow transactions send {filename} --args-json ""$(cat myfile.json)""` || `flow transactions send {filename}""$(wget -O- -q https://raw.githubusercontent.com/onflow/some-flow-repo/some-commit-hash-or-tag/path-to/arguments.json)"" `",0,include a clarification about how to provide the arguments of a transaction like a json file issue to be solved how to pass a json file for providing the arguments of a transaction using flow cli is not documented suggest a solution update the with clear instructions about how to do it flow transactions send filename args json cat myfile json flow transactions send filename wget o q ,05208782,27172243566.0,IssuesEvent,2023-02-17 20:35:23,OneDrive/onedrive-api-docs,https://api.github.com/repos/OneDrive/onedrive-api-docs,closed,"Embeddable URLs from the ""driveItem: preview"" endpoint fail to load ~20% of the time.",status:investigating Needs: Attention :wave: area:Previewers automation:Closed,"521#### Category522- [ ] Question523- [ ] Documentation issue524- [ x] Bug525 526#### Expected or Desired Behavior527 528Embeddable URL that should display the contents of the sharepoint office file in the web browser (as ready only). 529 530#### Observed Behavior531 532Fails about 20% of the time with JS errors on the viewer (through the link returned). When this occurs, the viewer does not load, and the page needs to be refreshed.533 534#### Steps to Reproduce535 536Call the ""driveItem: preview"" endpoint, receive an embeddable link to display within an iframe. Fails to load ~20% of the time.537 538Thank you.539",1.0,"Embeddable URLs from the ""driveItem: preview"" endpoint fail to load ~20% of the time. - 540#### Category541- [ ] Question542- [ ] Documentation issue543- [ x] Bug544 545#### Expected or Desired Behavior546 547Embeddable URL that should display the contents of the sharepoint office file in the web browser (as ready only). 548 549#### Observed Behavior550 551Fails about 20% of the time with JS errors on the viewer (through the link returned). When this occurs, the viewer does not load, and the page needs to be refreshed.552 553#### Steps to Reproduce554 555Call the ""driveItem: preview"" endpoint, receive an embeddable link to display within an iframe. Fails to load ~20% of the time.556 557Thank you.558",1,embeddable urls from the driveitem preview endpoint fail to load of the time category question documentation issue bug expected or desired behavior embeddable url that should display the contents of the sharepoint office file in the web browser as ready only observed behavior fails about of the time with js errors on the viewer through the link returned when this occurs the viewer does not load and the page needs to be refreshed steps to reproduce call the driveitem preview endpoint receive an embeddable link to display within an iframe fails to load of the time thank you ,15595755,20981764623.0,IssuesEvent,2022-03-28 20:42:38,willowtreeapps/vocable-ios,https://api.github.com/repos/willowtreeapps/vocable-ios,closed,[Test] Re-enable CustomCategoriesTests,automation,"We accidentally disabled the CustomCategoriesTests somehow. We should re-enable them so that we can get the test results during builds.560 561AC: 562All tests in CustomCategoriesTests are enabled and run during builds.563",1.0,"[Test] Re-enable CustomCategoriesTests - We accidentally disabled the CustomCategoriesTests somehow. We should re-enable them so that we can get the test results during builds.564 565AC: 566All tests in CustomCategoriesTests are enabled and run during builds.567",1, re enable customcategoriestests we accidentally disabled the customcategoriestests somehow we should re enable them so that we can get the test results during builds ac all tests in customcategoriestests are enabled and run during builds ,1568350149,31857391762.0,IssuesEvent,2023-09-15 08:28:28,microsoft/AzureStorageExplorer,https://api.github.com/repos/microsoft/AzureStorageExplorer,opened,Only 1000 entities are loaded when sorting by one column if there is a query clause under query mode,๐งช testing :gear: tables,"**Storage Explorer Version:** 1.32.0-dev (93)569**Build Number:** 20230915.2570**Branch:** main571**Platform/OS:** Windows 10/Linux Ubuntu 20.04/MacOS Ventura 13.5.2 (Apple M1 Pro)572**Architecture:** x64/x64/x64573**How Found:** Exploratory testing574**Regression From:** Not a regression575 576## Steps to Reproduce ##577 5781. Open 'Settings' -> Enable the setting 'Global Sort'.5792. Expand one storage account -> Tables.5803. Open one table which contains more than 1000 entities.5814. Click 'Query' -> Make sure there is at least one query clause.5825. Sort entities by one column.5836. Check whether all entities are loaded.584 585## Expected Experience ##586All entities are loaded.587 588## Actual Experience ##589Only 1000 entities are loaded.590 591## Additional Context ##592 5931. This issue doesn't reproduce when there is no query clause.5942. Here is the record:595596",1.0,"Only 1000 entities are loaded when sorting by one column if there is a query clause under query mode - **Storage Explorer Version:** 1.32.0-dev (93)597**Build Number:** 20230915.2598**Branch:** main599**Platform/OS:** Windows 10/Linux Ubuntu 20.04/MacOS Ventura 13.5.2 (Apple M1 Pro)600**Architecture:** x64/x64/x64601**How Found:** Exploratory testing602**Regression From:** Not a regression603 604## Steps to Reproduce ##605 6061. Open 'Settings' -> Enable the setting 'Global Sort'.6072. Expand one storage account -> Tables.6083. Open one table which contains more than 1000 entities.6094. Click 'Query' -> Make sure there is at least one query clause.6105. Sort entities by one column.6116. Check whether all entities are loaded.612 613## Expected Experience ##614All entities are loaded.615 616## Actual Experience ##617Only 1000 entities are loaded.618 619## Additional Context ##620 6211. This issue doesn't reproduce when there is no query clause.6222. Here is the record:623624",0,only entities are loaded when sorting by one column if there is a query clause under query mode storage explorer version dev build number branch main platform os windows linux ubuntu macos ventura apple pro architecture how found exploratory testing regression from not a regression steps to reproduce open settings enable the setting global sort expand one storage account tables open one table which contains more than entities click query make sure there is at least one query clause sort entities by one column check whether all entities are loaded expected experience all entities are loaded actual experience only entities are loaded additional context this issue doesn t reproduce when there is no query clause here is the record ,0625272092,20732962109.0,IssuesEvent,2022-03-14 11:08:12,Arquisoft/dede_en2b,https://api.github.com/repos/Arquisoft/dede_en2b,closed,Contribution for deliverable 1 - Diego Martรญn,documentation v0.1,"I have developed part of point 1 and 4 of the documentation, the last one to be expanded. Moreover I was in charge of writting the topics discussed on the second reunion. And last but not least, I checked beforehand the instalation of the software and helped my teammates, since some of them had trouble with npm and ruby.",1.0,"Contribution for deliverable 1 - Diego Martรญn - I have developed part of point 1 and 4 of the documentation, the last one to be expanded. Moreover I was in charge of writting the topics discussed on the second reunion. And last but not least, I checked beforehand the instalation of the software and helped my teammates, since some of them had trouble with npm and ruby.",0,contribution for deliverable diego martรญn i have developed part of point and of the documentation the last one to be expanded moreover i was in charge of writting the topics discussed on the second reunion and last but not least i checked beforehand the instalation of the software and helped my teammates since some of them had trouble with npm and ruby ,062642905,5545726310.0,IssuesEvent,2017-03-22 22:21:22,gustafl/youtube-blacklist-chrome-extension,https://api.github.com/repos/gustafl/youtube-blacklist-chrome-extension,opened,Design the popup,design,"It should contain the following, in order:627 628* Logo629* Title text630* Version number631* Disable/enable toggle button632* Number of blacklisted users633* Number of comments hidden on page634* Link to extension in Web Store",1.0,"Design the popup - It should contain the following, in order:635 636* Logo637* Title text638* Version number639* Disable/enable toggle button640* Number of blacklisted users641* Number of comments hidden on page642* Link to extension in Web Store",0,design the popup it should contain the following in order logo title text version number disable enable toggle button number of blacklisted users number of comments hidden on page link to extension in web store,0643171720,27168183667.0,IssuesEvent,2023-02-17 16:58:18,Lightning-AI/lightning,https://api.github.com/repos/Lightning-AI/lightning,closed,"Is `precision=""mixed""` redundant?",refactor design precision: amp,"## Proposed refactoring or deprecation644 645Does `precision=""mixed""` act differently to `precision=16` in any way?646 647I understand that ""mixed"" is more correct as 16-bit precision can still run some computations in 32-bit.648 649### Motivation650 651In https://github.com/PyTorchLightning/pytorch-lightning/pull/9763 I noticed we did not even have a `PrecisionType` for `""mixed""`.652 653There's a single test in the codebase passing the ""mixed"" value:654 655https://github.com/PyTorchLightning/pytorch-lightning/blob/master/tests/plugins/test_deepspeed_plugin.py#L153656 657And no mention at all of this value in the docs.658 659### Pitch660 661Have one value to set this, whether it is `16` or `""mixed""`. Most likely `16` since its the one widely used.662 663Otherwise, add tests for passing `""mixed""`664 665### Additional context666 667```python668$ grep -iIrn '""mixed""' pytorch_lightning669pytorch_lightning/plugins/training_type/sharded.py:62: is_fp16 = precision in (""mixed"", 16)670pytorch_lightning/plugins/training_type/fully_sharded.py:135: mixed_precision=precision == ""mixed"",671pytorch_lightning/plugins/training_type/ipu.py:42: if self.precision in (""mixed"", 16):672pytorch_lightning/plugins/training_type/deepspeed.py:405: dtype = torch.float16 if self.precision in (16, ""mixed"") else torch.float32673pytorch_lightning/plugins/training_type/deepspeed.py:473: dtype = torch.float16 if self.precision in (16, ""mixed"") else torch.float32674pytorch_lightning/plugins/training_type/deepspeed.py:602: if precision in (16, ""mixed""):675pytorch_lightning/plugins/precision/mixed.py:26: precision: Union[str, int] = ""mixed""676pytorch_lightning/plugins/precision/fully_sharded_native_amp.py:26: precision = ""mixed""677```678 679```python680$ grep -iIrn '""mixed""' tests681tests/plugins/test_deepspeed_plugin.py:153:@pytest.mark.parametrize(""precision"", [16, ""mixed""])682```683 684 685```python686$ grep -Irn 'mixed' docs | grep 'precision='687# no mention in the docs!688```689______________________________________________________________________690 691#### If you enjoy Lightning, check out our other projects! โก692 693<sub>694 695- [**Metrics**](https://github.com/PyTorchLightning/metrics): Machine learning metrics for distributed, scalable PyTorch applications.696 697- [**Flash**](https://github.com/PyTorchLightning/lightning-flash): The fastest way to get a Lightning baseline! A collection of tasks for fast prototyping, baselining, finetuning and solving problems with deep learning698 699- [**Bolts**](https://github.com/PyTorchLightning/lightning-bolts): Pretrained SOTA Deep Learning models, callbacks and more for research and production with PyTorch Lightning and PyTorch700 701- [**Lightning Transformers**](https://github.com/PyTorchLightning/lightning-transformers): Flexible interface for high performance research using SOTA Transformers leveraging Pytorch Lightning, Transformers, and Hydra.702 703</sub>704 705 706cc @justusschock @awaelchli @akihironitta @rohitgr7 @tchaton @borda @carmocca",1.0,"Is `precision=""mixed""` redundant? - ## Proposed refactoring or deprecation707 708Does `precision=""mixed""` act differently to `precision=16` in any way?709 710I understand that ""mixed"" is more correct as 16-bit precision can still run some computations in 32-bit.711 712### Motivation713 714In https://github.com/PyTorchLightning/pytorch-lightning/pull/9763 I noticed we did not even have a `PrecisionType` for `""mixed""`.715 716There's a single test in the codebase passing the ""mixed"" value:717 718https://github.com/PyTorchLightning/pytorch-lightning/blob/master/tests/plugins/test_deepspeed_plugin.py#L153719 720And no mention at all of this value in the docs.721 722### Pitch723 724Have one value to set this, whether it is `16` or `""mixed""`. Most likely `16` since its the one widely used.725 726Otherwise, add tests for passing `""mixed""`727 728### Additional context729 730```python731$ grep -iIrn '""mixed""' pytorch_lightning732pytorch_lightning/plugins/training_type/sharded.py:62: is_fp16 = precision in (""mixed"", 16)733pytorch_lightning/plugins/training_type/fully_sharded.py:135: mixed_precision=precision == ""mixed"",734pytorch_lightning/plugins/training_type/ipu.py:42: if self.precision in (""mixed"", 16):735pytorch_lightning/plugins/training_type/deepspeed.py:405: dtype = torch.float16 if self.precision in (16, ""mixed"") else torch.float32736pytorch_lightning/plugins/training_type/deepspeed.py:473: dtype = torch.float16 if self.precision in (16, ""mixed"") else torch.float32737pytorch_lightning/plugins/training_type/deepspeed.py:602: if precision in (16, ""mixed""):738pytorch_lightning/plugins/precision/mixed.py:26: precision: Union[str, int] = ""mixed""739pytorch_lightning/plugins/precision/fully_sharded_native_amp.py:26: precision = ""mixed""740```741 742```python743$ grep -iIrn '""mixed""' tests744tests/plugins/test_deepspeed_plugin.py:153:@pytest.mark.parametrize(""precision"", [16, ""mixed""])745```746 747 748```python749$ grep -Irn 'mixed' docs | grep 'precision='750# no mention in the docs!751```752______________________________________________________________________753 754#### If you enjoy Lightning, check out our other projects! โก755 756<sub>757 758- [**Metrics**](https://github.com/PyTorchLightning/metrics): Machine learning metrics for distributed, scalable PyTorch applications.759 760- [**Flash**](https://github.com/PyTorchLightning/lightning-flash): The fastest way to get a Lightning baseline! A collection of tasks for fast prototyping, baselining, finetuning and solving problems with deep learning761 762- [**Bolts**](https://github.com/PyTorchLightning/lightning-bolts): Pretrained SOTA Deep Learning models, callbacks and more for research and production with PyTorch Lightning and PyTorch763 764- [**Lightning Transformers**](https://github.com/PyTorchLightning/lightning-transformers): Flexible interface for high performance research using SOTA Transformers leveraging Pytorch Lightning, Transformers, and Hydra.765 766</sub>767 768 769cc @justusschock @awaelchli @akihironitta @rohitgr7 @tchaton @borda @carmocca",0,is precision mixed redundant proposed refactoring or deprecation does precision mixed act differently to precision in any way i understand that mixed is more correct as bit precision can still run some computations in bit motivation in i noticed we did not even have a precisiontype for mixed there s a single test in the codebase passing the mixed value and no mention at all of this value in the docs pitch have one value to set this whether it is or mixed most likely since its the one widely used otherwise add tests for passing mixed additional context python grep iirn mixed pytorch lightning pytorch lightning plugins training type sharded py is precision in mixed pytorch lightning plugins training type fully sharded py mixed precision precision mixed pytorch lightning plugins training type ipu py if self precision in mixed pytorch lightning plugins training type deepspeed py dtype torch if self precision in mixed else torch pytorch lightning plugins training type deepspeed py dtype torch if self precision in mixed else torch pytorch lightning plugins training type deepspeed py if precision in mixed pytorch lightning plugins precision mixed py precision union mixed pytorch lightning plugins precision fully sharded native amp py precision mixed python grep iirn mixed tests tests plugins test deepspeed plugin py pytest mark parametrize precision python grep irn mixed docs grep precision no mention in the docs if you enjoy lightning check out our other projects โก machine learning metrics for distributed scalable pytorch applications the fastest way to get a lightning baseline a collection of tasks for fast prototyping baselining finetuning and solving problems with deep learning pretrained sota deep learning models callbacks and more for research and production with pytorch lightning and pytorch flexible interface for high performance research using sota transformers leveraging pytorch lightning transformers and hydra cc justusschock awaelchli akihironitta tchaton borda carmocca,07701031,9201757206.0,IssuesEvent,2019-03-07 20:30:06,home-assistant/home-assistant,https://api.github.com/repos/home-assistant/home-assistant,closed,Home assistant interpreting non latin aliases in automations.yaml as non unique,component: automation waiting-for-reply,"**Home Assistant release with the issue:**7710.77.3772 773**Component/platform:**774automations.yaml775 776**Description of problem:**777 778automations.yaml with 2 or more automations like this:779 780```781- id: state_door_closed782 alias: ""ะกะพะพะฑัะธัั ะพ ะทะฐะบัััะธะธ ะดะฒะตัะธ""783 trigger:784 - entity_id: binary_sensor.home_door785 platform: state786 to: 'off'787 action:788 - data:789 message: ""ะะฒะตัั ะทะฐะบัััะฐ""790 service: notify.state791 792- id: state_door_opened793 alias: ""ะกะพะพะฑัะธัั ะพะฑ ะพัะบัััะธะธ ะดะฒะตัะธ""794 trigger:795 - entity_id: binary_sensor.home_door796 platform: state797 to: 'on'798 action:799 - data:800 message: ""ะะฒะตัั ะพัะบัััะฐ""801 service: notify.state802```803 804cause errors on Home Assistant start: ""Entity id already exists: automation._____"" because code using only latin symbols (in that case - spaces) and thinks that aliases same.805 806And it's not only one problem - on Home Assistant start that automations not loaded at all. 807**But if we made manual automations reload - they appear in list - and works - very strange (so work is possible!)**808 809So - we give id in english, alias - as we want to see in lists. And got errors. May be rename alias in friendly_name and works with it values like with friendly name, and unique name take from id? Automation Editor generates unique ids for example and aliases can be same (and fully latin) too...810So problem not in non latin symbols.",1.0,"Home assistant interpreting non latin aliases in automations.yaml as non unique - **Home Assistant release with the issue:**8110.77.3812 813**Component/platform:**814automations.yaml815 816**Description of problem:**817 818automations.yaml with 2 or more automations like this:819 820```821- id: state_door_closed822 alias: ""ะกะพะพะฑัะธัั ะพ ะทะฐะบัััะธะธ ะดะฒะตัะธ""823 trigger:824 - entity_id: binary_sensor.home_door825 platform: state826 to: 'off'827 action:828 - data:829 message: ""ะะฒะตัั ะทะฐะบัััะฐ""830 service: notify.state831 832- id: state_door_opened833 alias: ""ะกะพะพะฑัะธัั ะพะฑ ะพัะบัััะธะธ ะดะฒะตัะธ""834 trigger:835 - entity_id: binary_sensor.home_door836 platform: state837 to: 'on'838 action:839 - data:840 message: ""ะะฒะตัั ะพัะบัััะฐ""841 service: notify.state842```843 844cause errors on Home Assistant start: ""Entity id already exists: automation._____"" because code using only latin symbols (in that case - spaces) and thinks that aliases same.845 846And it's not only one problem - on Home Assistant start that automations not loaded at all. 847**But if we made manual automations reload - they appear in list - and works - very strange (so work is possible!)**848 849So - we give id in english, alias - as we want to see in lists. And got errors. May be rename alias in friendly_name and works with it values like with friendly name, and unique name take from id? Automation Editor generates unique ids for example and aliases can be same (and fully latin) too...850So problem not in non latin symbols.",1,home assistant interpreting non latin aliases in automations yaml as non unique home assistant release with the issue component platform automations yaml description of problem automations yaml with or more automations like this id state door closed alias ัะพะพะฑัะธัั ะพ ะทะฐะบัััะธะธ ะดะฒะตัะธ trigger entity id binary sensor home door platform state to off action data message ะดะฒะตัั ะทะฐะบัััะฐ service notify state id state door opened alias ัะพะพะฑัะธัั ะพะฑ ะพัะบัััะธะธ ะดะฒะตัะธ trigger entity id binary sensor home door platform state to on action data message ะดะฒะตัั ะพัะบัััะฐ service notify state cause errors on home assistant start entity id already exists automation because code using only latin symbols in that case spaces and thinks that aliases same and it s not only one problem on home assistant start that automations not loaded at all but if we made manual automations reload they appear in list and works very strange so work is possible so we give id in english alias as we want to see in lists and got errors may be rename alias in friendly name and works with it values like with friendly name and unique name take from id automation editor generates unique ids for example and aliases can be same and fully latin too so problem not in non latin symbols ,1851102249,16550524748.0,IssuesEvent,2021-05-28 08:03:34,Vento-Nuenenen/inowo,https://api.github.com/repos/Vento-Nuenenen/inowo,opened,CVE-2021-32640 (Medium) detected in ws-7.4.5.tgz,security vulnerability,"## CVE-2021-32640 - Medium Severity Vulnerability852<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>ws-7.4.5.tgz</b></p></summary>853 854<p>Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js</p>855<p>Library home page: <a href=""https://registry.npmjs.org/ws/-/ws-7.4.5.tgz"">https://registry.npmjs.org/ws/-/ws-7.4.5.tgz</a></p>856<p>Path to dependency file: inowo/package.json</p>857<p>Path to vulnerable library: inowo/node_modules/ws/package.json</p>858<p>859 860Dependency Hierarchy:861 - laravel-mix-6.0.19.tgz (Root Library)862 - webpack-dev-server-4.0.0-beta.2.tgz863 - :x: **ws-7.4.5.tgz** (Vulnerable Library)864<p>Found in HEAD commit: <a href=""https://github.com/Vento-Nuenenen/inowo/commit/22cf1dc4dcbb30afa68b88767bdb7da1e5c84a24"">22cf1dc4dcbb30afa68b88767bdb7da1e5c84a24</a></p>865<p>Found in base branch: <b>master</b></p>866</p>867</details>868<p></p>869<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> Vulnerability Details</summary>870<p> 871 872ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.873 874<p>Publish Date: 2021-05-25875<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2021-32640>CVE-2021-32640</a></p>876</p>877</details>878<p></p>879<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>5.3</b>)</summary>880<p>881 882Base Score Metrics:883- Exploitability Metrics:884 - Attack Vector: Network885 - Attack Complexity: Low886 - Privileges Required: None887 - User Interaction: None888 - Scope: Unchanged889- Impact Metrics:890 - Confidentiality Impact: None891 - Integrity Impact: None892 - Availability Impact: Low893</p>894For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.895</p>896</details>897<p></p>898<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>899<p>900 901<p>Type: Upgrade version</p>902<p>Origin: <a href=""https://github.com/websockets/ws/security/advisories/GHSA-6fc8-4gx4-v693"">https://github.com/websockets/ws/security/advisories/GHSA-6fc8-4gx4-v693</a></p>903<p>Release Date: 2021-05-25</p>904<p>Fix Resolution: ws - 7.4.6</p>905 906</p>907</details>908<p></p>909 910***911Step up your Open Source Security Game with WhiteSource [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)",True,"CVE-2021-32640 (Medium) detected in ws-7.4.5.tgz - ## CVE-2021-32640 - Medium Severity Vulnerability912<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>ws-7.4.5.tgz</b></p></summary>913 914<p>Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js</p>915<p>Library home page: <a href=""https://registry.npmjs.org/ws/-/ws-7.4.5.tgz"">https://registry.npmjs.org/ws/-/ws-7.4.5.tgz</a></p>916<p>Path to dependency file: inowo/package.json</p>917<p>Path to vulnerable library: inowo/node_modules/ws/package.json</p>918<p>919 920Dependency Hierarchy:921 - laravel-mix-6.0.19.tgz (Root Library)922 - webpack-dev-server-4.0.0-beta.2.tgz923 - :x: **ws-7.4.5.tgz** (Vulnerable Library)924<p>Found in HEAD commit: <a href=""https://github.com/Vento-Nuenenen/inowo/commit/22cf1dc4dcbb30afa68b88767bdb7da1e5c84a24"">22cf1dc4dcbb30afa68b88767bdb7da1e5c84a24</a></p>925<p>Found in base branch: <b>master</b></p>926</p>927</details>928<p></p>929<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20> Vulnerability Details</summary>930<p> 931 932ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.933 934<p>Publish Date: 2021-05-25935<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2021-32640>CVE-2021-32640</a></p>936</p>937</details>938<p></p>939<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>5.3</b>)</summary>940<p>941 942Base Score Metrics:943- Exploitability Metrics:944 - Attack Vector: Network945 - Attack Complexity: Low946 - Privileges Required: None947 - User Interaction: None948 - Scope: Unchanged949- Impact Metrics:950 - Confidentiality Impact: None951 - Integrity Impact: None952 - Availability Impact: Low953</p>954For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.955</p>956</details>957<p></p>958<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>959<p>960 961<p>Type: Upgrade version</p>962<p>Origin: <a href=""https://github.com/websockets/ws/security/advisories/GHSA-6fc8-4gx4-v693"">https://github.com/websockets/ws/security/advisories/GHSA-6fc8-4gx4-v693</a></p>963<p>Release Date: 2021-05-25</p>964<p>Fix Resolution: ws - 7.4.6</p>965 966</p>967</details>968<p></p>969 970***971Step up your Open Source Security Game with WhiteSource [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)",0,cve medium detected in ws tgz cve medium severity vulnerability vulnerable library ws tgz simple to use blazing fast and thoroughly tested websocket client and server for node js library home page a href path to dependency file inowo package json path to vulnerable library inowo node modules ws package json dependency hierarchy laravel mix tgz root library webpack dev server beta tgz x ws tgz vulnerable library found in head commit a href found in base branch master vulnerability details ws is an open source websocket client and server library for node js a specially crafted value of the sec websocket protocol header can be used to significantly slow down a ws server the vulnerability has been fixed in ws in vulnerable versions of ws the issue can be mitigated by reducing the maximum allowed length of the request headers using the and or the options publish date url a href cvss score details base score metrics exploitability metrics attack vector network attack complexity low privileges required none user interaction none scope unchanged impact metrics confidentiality impact none integrity impact none availability impact low for more information on scores click a href suggested fix type upgrade version origin a href release date fix resolution ws step up your open source security game with whitesource ,0972648240,21179996761.0,IssuesEvent,2022-04-08 06:55:25,AY2122S2-CS2103T-T13-4/tp,https://api.github.com/repos/AY2122S2-CS2103T-T13-4/tp,closed,GUI Undo/Redo bug,type.Bug priority.MEDIUM,"To replicate, here are the steps:9731. Type `add`9742. Close `AddWindow`9753. Type `undo`976 977No commands should be undone, and if any action should be taken, it would be to reopen `AddWindow` (but I think this one would be complicated)978 979Alternatively, if you were to add a new `Person`..9801. Type `add`9812. Fill in details of new `Person`9823. Submit9834. Type undo. It gives the correct behaviour of undoing the adding of a `Person`9845. Type undo again. It gives the wrong behaviour and reports `Undo Success!` when correct one should report `No more commands to undo!`, since typing `add` is just a intermediary to open up `AddWindow` rather than a command that modifies.985",1.0,"GUI Undo/Redo bug - To replicate, here are the steps:9861. Type `add`9872. Close `AddWindow`9883. Type `undo`989 990No commands should be undone, and if any action should be taken, it would be to reopen `AddWindow` (but I think this one would be complicated)991 992Alternatively, if you were to add a new `Person`..9931. Type `add`9942. Fill in details of new `Person`9953. Submit9964. Type undo. It gives the correct behaviour of undoing the adding of a `Person`9975. Type undo again. It gives the wrong behaviour and reports `Undo Success!` when correct one should report `No more commands to undo!`, since typing `add` is just a intermediary to open up `AddWindow` rather than a command that modifies.998",0,gui undo redo bug to replicate here are the steps type add close addwindow type undo no commands should be undone and if any action should be taken it would be to reopen addwindow but i think this one would be complicated alternatively if you were to add a new person type add fill in details of new person submit type undo it gives the correct behaviour of undoing the adding of a person type undo again it gives the wrong behaviour and reports undo success when correct one should report no more commands to undo since typing add is just a intermediary to open up addwindow rather than a command that modifies ,09991099,9461136796.0,IssuesEvent,2019-04-17 12:49:03,nf-core/tools,https://api.github.com/repos/nf-core/tools,opened,Automate Releases,automation question template,"Since we already insist on having people work on `dev` branches & `master` branches only incorporating stable code, we could also produce a way of making automated releases too:1000 1001https://github.com/semantic-release/semantic-release1002 1003This would only require:1004 1005- Setting the `master` branch protected for everyone, except for PRs coming from `dev`1006- Forcing everyone to NEVER merge to `master` except for releases that have been tested on `dev` (which we anyways do)1007 1008Could then configure the method above to make a release whenever coming from `master` and something has been changed. If people then also use the `CHANGELOG.md`, it would automatically do proper and nice releases :-) 1009 1010",1.0,"Automate Releases - Since we already insist on having people work on `dev` branches & `master` branches only incorporating stable code, we could also produce a way of making automated releases too:1011 1012https://github.com/semantic-release/semantic-release1013 1014This would only require:1015 1016- Setting the `master` branch protected for everyone, except for PRs coming from `dev`1017- Forcing everyone to NEVER merge to `master` except for releases that have been tested on `dev` (which we anyways do)1018 1019Could then configure the method above to make a release whenever coming from `master` and something has been changed. If people then also use the `CHANGELOG.md`, it would automatically do proper and nice releases :-) 1020 1021",1,automate releases since we already insist on having people work on dev branches master branches only incorporating stable code we could also produce a way of making automated releases too this would only require setting the master branch protected for everyone except for prs coming from dev forcing everyone to never merge to master except for releases that have been tested on dev which we anyways do could then configure the method above to make a release whenever coming from master and something has been changed if people then also use the changelog md it would automatically do proper and nice releases ,110221166,9607666582.0,IssuesEvent,2019-05-11 21:03:54,riemers/home-assistant-config,https://api.github.com/repos/riemers/home-assistant-config,opened,Make a movie mode,Automation Todo,"- Dim lights (if at night time)1023- Only turn on movie mode is receiver is turned on1024- Turn on subwoofer (add a plug in between, safes usage)1025- Turn sun screen down (day and night, awefull pedestrian stoplight bluring my vision)1026",1.0,"Make a movie mode - - Dim lights (if at night time)1027- Only turn on movie mode is receiver is turned on1028- Turn on subwoofer (add a plug in between, safes usage)1029- Turn sun screen down (day and night, awefull pedestrian stoplight bluring my vision)1030",1,make a movie mode dim lights if at night time only turn on movie mode is receiver is turned on turn on subwoofer add a plug in between safes usage turn sun screen down day and night awefull pedestrian stoplight bluring my vision ,11031107080,16751510521.0,IssuesEvent,2021-06-12 01:03:36,Tim-sandbox/EZBuggyPrioritize,https://api.github.com/repos/Tim-sandbox/EZBuggyPrioritize,opened,CVE-2018-3258 (High) detected in mysql-connector-java-5.1.25.jar,security vulnerability,"## CVE-2018-3258 - High Severity Vulnerability1032<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>mysql-connector-java-5.1.25.jar</b></p></summary>1033 1034<p>MySQL JDBC Type 4 driver</p>1035<p>Library home page: <a href=""http://dev.mysql.com/doc/connector-j/en/"">http://dev.mysql.com/doc/connector-j/en/</a></p>1036<p>Path to dependency file: EZBuggyPrioritize/pom.xml</p>1037<p>Path to vulnerable library: EZBuggyPrioritize/target/easybuggy-1-SNAPSHOT/WEB-INF/lib/mysql-connector-java-5.1.25.jar,canner/.m2/repository/mysql/mysql-connector-java/5.1.25/mysql-connector-java-5.1.25.jar</p>1038<p>1039 1040Dependency Hierarchy:1041 - :x: **mysql-connector-java-5.1.25.jar** (Vulnerable Library)1042<p>Found in base branch: <b>main</b></p>1043</p>1044</details>1045<p></p>1046<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> Vulnerability Details</summary>1047<p> 1048 1049Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).1050 1051<p>Publish Date: 2018-10-171052<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2018-3258>CVE-2018-3258</a></p>1053</p>1054</details>1055<p></p>1056<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>8.8</b>)</summary>1057<p>1058 1059Base Score Metrics:1060- Exploitability Metrics:1061 - Attack Vector: Network1062 - Attack Complexity: Low1063 - Privileges Required: Low1064 - User Interaction: None1065 - Scope: Unchanged1066- Impact Metrics:1067 - Confidentiality Impact: High1068 - Integrity Impact: High1069 - Availability Impact: High1070</p>1071For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.1072</p>1073</details>1074<p></p>1075<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>1076<p>1077 1078<p>Type: Upgrade version</p>1079<p>Origin: <a href=""https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3258"">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3258</a></p>1080<p>Release Date: 2018-10-17</p>1081<p>Fix Resolution: mysql:mysql-connector-java:8.0.13</p>1082 1083</p>1084</details>1085<p></p>1086 1087***1088:rescue_worker_helmet: Automatic Remediation is available for this issue1089<!-- <REMEDIATE>{""isOpenPROnVulnerability"":true,""isPackageBased"":true,""isDefaultBranch"":true,""packages"":[{""packageType"":""Java"",""groupId"":""mysql"",""packageName"":""mysql-connector-java"",""packageVersion"":""5.1.25"",""packageFilePaths"":[""/pom.xml""],""isTransitiveDependency"":false,""dependencyTree"":""mysql:mysql-connector-java:5.1.25"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""mysql:mysql-connector-java:8.0.13""}],""baseBranches"":[""main""],""vulnerabilityIdentifier"":""CVE-2018-3258"",""vulnerabilityDetails"":""Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)."",""vulnerabilityUrl"":""https://vuln.whitesourcesoftware.com/vulnerability/CVE-2018-3258"",""cvss3Severity"":""high"",""cvss3Score"":""8.8"",""cvss3Metrics"":{""A"":""High"",""AC"":""Low"",""PR"":""Low"",""S"":""Unchanged"",""C"":""High"",""UI"":""None"",""AV"":""Network"",""I"":""High""},""extraData"":{}}</REMEDIATE> -->",True,"CVE-2018-3258 (High) detected in mysql-connector-java-5.1.25.jar - ## CVE-2018-3258 - High Severity Vulnerability1090<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Library - <b>mysql-connector-java-5.1.25.jar</b></p></summary>1091 1092<p>MySQL JDBC Type 4 driver</p>1093<p>Library home page: <a href=""http://dev.mysql.com/doc/connector-j/en/"">http://dev.mysql.com/doc/connector-j/en/</a></p>1094<p>Path to dependency file: EZBuggyPrioritize/pom.xml</p>1095<p>Path to vulnerable library: EZBuggyPrioritize/target/easybuggy-1-SNAPSHOT/WEB-INF/lib/mysql-connector-java-5.1.25.jar,canner/.m2/repository/mysql/mysql-connector-java/5.1.25/mysql-connector-java-5.1.25.jar</p>1096<p>1097 1098Dependency Hierarchy:1099 - :x: **mysql-connector-java-5.1.25.jar** (Vulnerable Library)1100<p>Found in base branch: <b>main</b></p>1101</p>1102</details>1103<p></p>1104<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png' width=19 height=20> Vulnerability Details</summary>1105<p> 1106 1107Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).1108 1109<p>Publish Date: 2018-10-171110<p>URL: <a href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2018-3258>CVE-2018-3258</a></p>1111</p>1112</details>1113<p></p>1114<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>8.8</b>)</summary>1115<p>1116 1117Base Score Metrics:1118- Exploitability Metrics:1119 - Attack Vector: Network1120 - Attack Complexity: Low1121 - Privileges Required: Low1122 - User Interaction: None1123 - Scope: Unchanged1124- Impact Metrics:1125 - Confidentiality Impact: High1126 - Integrity Impact: High1127 - Availability Impact: High1128</p>1129For more information on CVSS3 Scores, click <a href=""https://www.first.org/cvss/calculator/3.0"">here</a>.1130</p>1131</details>1132<p></p>1133<details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary>1134<p>1135 1136<p>Type: Upgrade version</p>1137<p>Origin: <a href=""https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3258"">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3258</a></p>1138<p>Release Date: 2018-10-17</p>1139<p>Fix Resolution: mysql:mysql-connector-java:8.0.13</p>1140 1141</p>1142</details>1143<p></p>1144 1145***1146:rescue_worker_helmet: Automatic Remediation is available for this issue1147<!-- <REMEDIATE>{""isOpenPROnVulnerability"":true,""isPackageBased"":true,""isDefaultBranch"":true,""packages"":[{""packageType"":""Java"",""groupId"":""mysql"",""packageName"":""mysql-connector-java"",""packageVersion"":""5.1.25"",""packageFilePaths"":[""/pom.xml""],""isTransitiveDependency"":false,""dependencyTree"":""mysql:mysql-connector-java:5.1.25"",""isMinimumFixVersionAvailable"":true,""minimumFixVersion"":""mysql:mysql-connector-java:8.0.13""}],""baseBranches"":[""main""],""vulnerabilityIdentifier"":""CVE-2018-3258"",""vulnerabilityDetails"":""Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)."",""vulnerabilityUrl"":""https://vuln.whitesourcesoftware.com/vulnerability/CVE-2018-3258"",""cvss3Severity"":""high"",""cvss3Score"":""8.8"",""cvss3Metrics"":{""A"":""High"",""AC"":""Low"",""PR"":""Low"",""S"":""Unchanged"",""C"":""High"",""UI"":""None"",""AV"":""Network"",""I"":""High""},""extraData"":{}}</REMEDIATE> -->",0,cve high detected in mysql connector java jar cve high severity vulnerability vulnerable library mysql connector java jar mysql jdbc type driver library home page a href path to dependency file ezbuggyprioritize pom xml path to vulnerable library ezbuggyprioritize target easybuggy snapshot web inf lib mysql connector java jar canner repository mysql mysql connector java mysql connector java jar dependency hierarchy x mysql connector java jar vulnerable library found in base branch main vulnerability details vulnerability in the mysql connectors component of oracle mysql subcomponent connector j supported versions that are affected are and prior easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise mysql connectors successful attacks of this vulnerability can result in takeover of mysql connectors cvss base score confidentiality integrity and availability impacts cvss vector cvss av n ac l pr l ui n s u c h i h a h publish date url a href cvss score details base score metrics exploitability metrics attack vector network attack complexity low privileges required low user interaction none scope unchanged impact metrics confidentiality impact high integrity impact high availability impact high for more information on scores click a href suggested fix type upgrade version origin a href release date fix resolution mysql mysql connector java rescue worker helmet automatic remediation is available for this issue isopenpronvulnerability true ispackagebased true isdefaultbranch true packages istransitivedependency false dependencytree mysql mysql connector java isminimumfixversionavailable true minimumfixversion mysql mysql connector java basebranches vulnerabilityidentifier cve vulnerabilitydetails vulnerability in the mysql connectors component of oracle mysql subcomponent connector j supported versions that are affected are and prior easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise mysql connectors successful attacks of this vulnerability can result in takeover of mysql connectors cvss base score confidentiality integrity and availability impacts cvss vector cvss av n ac l pr l ui n s u c h i h a h vulnerabilityurl ,011484683,17200692041.0,IssuesEvent,2021-07-17 06:44:10,home-assistant/core,https://api.github.com/repos/home-assistant/core,closed,Time Condition problem with both After and Before fields,integration: automation stale,"### The problem1149 1150I have an automation to switch on/off a plug, which is triggered from two time-only input_datetime helpers (one for each of on/off) and a device-tracker presence boolean grouped into group.inhabitants. Then there are two choose actions, one for on one for off, determined by various conditions.1151 1152The triggers1153```1154trigger:1155 - platform: state1156 entity_id: group.inhabitants1157 - platform: time1158 at: input_datetime.plug_coffee_on1159 - platform: time1160 at: input_datetime.plug_coffee_off1161```1162 1163The condition for on:1164```1165 conditions:1166 - condition: and1167 conditions:1168 - condition: time1169 after: input_datetime.plug_coffee_on1170 before: input_datetime.plug_coffee_off1171 - condition: state1172 entity_id: group.inhabitants1173 state: 'on'1174```1175The problem is that the on choose branch is executed when the OFF time helper is triggered, despite its being after the OFF time. It seems that the time condition in this case ignores the before statement. 1176 1177You can see this to be the case in the UI automation editor. There, the before condition is in fact empty. When I try to fix it up, by entering the proper helper in the UI and saving it, it is again empty when I reopen the automation editor (see the screenshot). Nothing changes in the YAML.1178 11791180 1181I've pasted the whole automation below, in case it is something strange in some other part of it that is causing this behaviour.1182 1183### What is version of Home Assistant Core has the issue?1184 11852021.4.31186 1187### What was the last working version of Home Assistant Core?1188 1189?1190 1191### What type of installation are you running?1192 1193Home Assistant OS1194 1195### Integration causing the issue1196 1197Automation1198 1199### Link to integration documentation on our website1200 