🔒 [IBM OSPO Security Notification] — IBM/text-generation-inference
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.
💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.
Attention: @joerunde @Nhan-Hoang
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Deadline |
Fix PR |
| 🟠 high |
CVE-2026-69249 |
cryptography |
>= 42.0.0, < 49.0.0 |
49.0.0 |
2026-10-10 |
— |
| 🟡 medium |
CVE-2026-69112 |
accelerate |
<= 1.14.0 |
— |
2026-12-09 |
— |
Code Scanning Alerts
| Severity |
Rule |
Tool |
Deadline |
| 🟡 medium |
actions/missing-workflow-permissions |
CodeQL |
2026-12-08 |
| 🟡 medium |
actions/missing-workflow-permissions |
CodeQL |
2026-12-08 |
Secret Scanning Alerts
No open secret scanning alerts.
🔒 [IBM OSPO Security Notification] — IBM/text-generation-inference
Attention: @joerunde @Nhan-Hoang
Dependabot Alerts
Code Scanning Alerts
Secret Scanning Alerts
No open secret scanning alerts.