Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

Patch

org.springframework.data:spring-data-mongodb 3.2.7

Back to all
Package Version

org.springframework.data:spring-data-mongodb 3.2.7

Package Version Scores

Overall
0
/10
Security
8
Activity
8
Popularity
7
Quality
6
Quality
Pull Requests from Bots
Pull requests from bot accounts indicate that the project is using automation for development tasks.
Quality
Pull Requests from Bots
Pull requests from bot accounts indicate that the project is using automation for development tasks.

Endor Patches

Patch Name
CVEs fixed
Lines of Code Changed
66900dac93d667780a3e7f2a
CVEs Fixed
C
1
H
0
+171
-12

Vulnerabilities Fixed

Get the Patch Instantly Without Upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

References

Basic Information

Ecosystem
Release Date
LINES OF CODE CHANGED
+171
-12
-
on latest patch
License
Patch Available

Get the Patch Instantly

Secure your app without upgrading.
Fix Without Upgrading
{
"items": [
{
"title": "Recent Commit Activity",
"description": "Recent commit activity indicates that the project is active",
"category": "activity",
"type": "upscore"
},
{
"title": "Most Commits are Verified",
"description": "A large fraction of the commits in this repository are verified; this shows that security best practices are followed",
"category": "code quality",
"type": "upscore"
},
{
"title": "Continuous Commit Activity",
"description": "Continuous commit activity indicates that the project is active",
"category": "activity",
"type": "upscore"
},
{
"title": "Consistent Commit Activity",
"description": "Consistent commit activity over longer periods of time indicates that the project is active",
"category": "activity",
"type": "upscore"
},
{
"title": "Recent Issue Activity",
"description": "Recent issue activity indicates that the project is in active development",
"category": "activity",
"type": "upscore"
},
{
"title": "Issues with Labels",
"description": "Attaching labels to issues allows for better tracking of issue activity in the project",
"category": "code quality",
"type": "upscore"
},
{
"title": "Pull Requests Have Labels",
"description": "Attaching labels to pull requests helps organize the development activity in the project",
"category": "code quality",
"type": "upscore"
},
{
"title": "Limited Activity From Corporate Accounts",
"description": "Lack of activity from corporate affiliated accounts indicates that the project may not have reliable backing and support",
"category": "activity",
"type": "downscore"
},
{
"title": "Activity from Reputable Accounts",
"description": "High activity from reputable accounts is an indication that the repository is well maintained. An account is considered reputable if it participates in multiple open source projects and has a high rating in GitHub",
"category": "activity",
"type": "upscore"
},
{
"title": "Small Number of Maintainers",
"description": "The majority of the repository's activity comes from a very small number of accounts, the project could be at risk if these accounts can not continue their contributions",
"category": "activity",
"type": "downscore"
},
{
"title": "First Major Release Milestone Achieved",
"description": "The repository has reached 1.0 release status, this is a sign of maturity",
"category": "code quality",
"type": "upscore"
},
{
"title": "Older Releases are Maintained",
"description": "The repository keeps releasing updates to earlier release trains, this is a sign of a commitment to maintaining and supporting the users of the project",
"category": "activity",
"type": "upscore"
},
{
"title": "Frequent Releases",
"description": "The repository has frequent releases, this is a sign of a commitment to maintaining and supporting the codebase",
"category": "activity",
"type": "upscore"
},
{
"title": "Recent Release Activity",
"description": "The repository has some very recent releases and this shows that it is actively maintained",
"category": "activity",
"type": "upscore"
},
{
"title": "Organization Repository",
"description": "When a repository belongs to an organization there is a lower risk of it getting abandoned in the future",
"category": "activity",
"type": "upscore"
},
{
"title": "No Known Vulnerabilities for this Version",
"description": "No vulnerabilities discovered in this version of the repository indicates that this is a version that is safe to use. Analysis only considers vulnerabilities associated with this repository and not its dependencies. Vulnerability information is based on OSV.dev data and Endor's vulnerability database",
"category": "security",
"type": "upscore"
},
{
"title": "Has Stars",
"description": "Having some stars indicates interest in the project. ",
"category": "popularity",
"type": "upscore"
},
{
"title": "Has Forks",
"description": "Having some forks shows an interest in the project",
"category": "popularity",
"type": "neutral"
},
{
"title": "Has Subscribers",
"description": "Having subscribers indicates interest in the project",
"category": "popularity",
"type": "upscore"
},
{
"title": "Repository has Documentation",
"description": "Documentation makes a package easier to understand and use",
"category": "code quality",
"type": "upscore"
},
{
"title": "No Automated Build System",
"description": "Reproducible builds using makefiles or CI systems allow verification that no modifications, such as vulnerabilities or backdoors, have been introduced during a package's build process",
"category": "code quality",
"type": "downscore"
},
{
"title": "Repository Contains Binary Files",
"description": "When a repository contains binary files it is harder to analyze and assess its functionality and risks",
"category": "code quality",
"type": "downscore"
},
{
"title": "No Best Practices Files",
"description": "The repository does not have any of the files that typically explain basic operational aspects of the project, this may be an indication that the project is not well maintained",
"category": "code quality",
"type": "downscore"
}
]
}