Skip to content

azure-cognitiveservices-speech SDK Vulnerability Issue Due to License Type #40038

Open
@hifaz1012

Description

@hifaz1012
  • azure-cognitiveservices-speech:
  • 1.42.0
  • Windows
  • 3.11:

Describe the bug
When customer source code was scanned using Azure DevOps Vulnerability Scanner Sonatype azure-cognitiveservices-speech SDK was detected as High Risk.

Image

The issue is probably due to license type and therefore detected as threat. The license is set as "Other/Proprietary," whereas typically, other Azure SDKs have an "MIT License."

Image

References: -

https://help.sonatype.com/en/license-threat-groups.html

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ClientThis issue points to a problem in the data-plane of the library.Cognitive - SpeechService AttentionWorkflow: This issue is responsible by Azure service team.bugThis issue requires a change to an existing behavior in the product in order to be resolved.customer-reportedIssues that are reported by GitHub users external to the Azure organization.issue-addressedWorkflow: The Azure SDK team believes it to be addressed and ready to close.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions