Lucene search

K

Github Action Merge Dependabot Security Vulnerabilities

cve
cve

CVE-2022-29220

github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the proper GPG key. There is just a check if the actor is set t...

6.5CVSS

6.3AI Score

0.001EPSS

2022-05-31 04:15 PM
48
5