Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

Patch

org.apache.thrift:libthrift 0.13.0

Back to all
Package Version

org.apache.thrift:libthrift 0.13.0

Package Version Scores

Overall
0
/10
Security
8
Activity
8
Popularity
8
Quality
6
Quality
Pull Requests from Bots
Pull requests from bot accounts indicate that the project is using automation for development tasks.
Quality
Pull Requests from Bots
Pull requests from bot accounts indicate that the project is using automation for development tasks.

Endor Patches

Patch Name
CVEs fixed
Lines of Code Changed
66d76b86b99c69fd01f4353d
CVEs Fixed
C
0
H
1
+4074
-113

Get the Patch Instantly Without Upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

References

Basic Information

Ecosystem
Release Date
LINES OF CODE CHANGED
+4074
-113
-
on latest patch
License
Patch Available

Get the Patch Instantly

Secure your app without upgrading.
Fix Without Upgrading
{
"items": [
{
"title": "Recent Commit Activity",
"description": "Recent commit activity indicates that the project is active",
"category": "activity",
"type": "upscore"
},
{
"title": "Regular Code Review",
"description": "A large faction of the commits in this repository are associated with a pull request; this shows that development best practices are followed",
"category": "code quality",
"type": "upscore"
},
{
"title": "Continuous Commit Activity",
"description": "Continuous commit activity indicates that the project is active",
"category": "activity",
"type": "upscore"
},
{
"title": "Recent Pull Request Activity",
"description": "Recent pull request activity indicates that the project is active",
"category": "activity",
"type": "upscore"
},
{
"title": "Pull Requests Have Labels",
"description": "Attaching labels to pull requests helps organize the development activity in the project",
"category": "code quality",
"type": "upscore"
},
{
"title": "Pull Requests from Bots",
"description": "Pull requests from bot accounts indicate that the project is using automation for development tasks",
"category": "code quality",
"type": "upscore"
},
{
"title": "Pull Requests From Dependency Management Bots",
"description": "Pull requests from dependency management bot accounts indicate that the project is using automation to keep its dependencies up to date",
"category": "code quality",
"type": "upscore"
},
{
"title": "Activity From Corporate Accounts",
"description": "Activity from corporate affiliated accounts indicates that the project may have reliable backing and support",
"category": "activity",
"type": "upscore"
},
{
"title": "Activity From Bot Accounts",
"description": "Activity from bot accounts shows that the project is using automation for some development tasks",
"category": "code quality",
"type": "upscore"
},
{
"title": "Releases Have Popular Artifacts",
"description": "Some of the released artifacts of the repository have been downloaded many times, this means the project is popular",
"category": "popularity",
"type": "upscore"
},
{
"title": "Recent Release Activity",
"description": "The repository has some very recent releases and this shows that it is actively maintained",
"category": "activity",
"type": "upscore"
},
{
"title": "Releases do not Follow SemVer",
"description": "The repository has releases that do not follow the SemVer standard, this goes against best practices",
"category": "code quality",
"type": "downscore"
},
{
"title": "Older Releases are Maintained",
"description": "The repository keeps releasing updates to earlier release trains, this is a sign of a commitment to maintaining and supporting the users of the project",
"category": "activity",
"type": "upscore"
},
{
"title": "Organization Repository",
"description": "When a repository belongs to an organization there is a lower risk of it getting abandoned in the future",
"category": "activity",
"type": "upscore"
},
{
"title": "Outdated Release",
"description": "This release is old and has been superseded by multiple newer releases, it should not be used",
"category": "code quality",
"type": "downscore"
},
{
"title": "No Known Vulnerabilities for this Version",
"description": "No vulnerabilities discovered in this version of the repository indicates that this is a version that is safe to use. Analysis only considers vulnerabilities associated with this repository and not its dependencies. Vulnerability information is based on OSV.dev data and Endor's vulnerability database",
"category": "security",
"type": "upscore"
},
{
"title": "Contributions From Many Reputable Accounts",
"description": "A large number of reputable contributors affiliated with the project indicates that the project is reliable. An account is considered reputable if it participates in multiple open source projects and has a high rating in GitHub",
"category": "popularity",
"type": "upscore"
},
{
"title": "Many Stars",
"description": "A very high number of stars indicates high interest in the project",
"category": "popularity",
"type": "upscore"
},
{
"title": "Many Forks",
"description": "Many forks show an active interest in the project",
"category": "popularity",
"type": "upscore"
},
{
"title": "Many Subscribers",
"description": "A very large number of subscribers indicates an active interest in the project",
"category": "popularity",
"type": "upscore"
},
{
"title": "No Automated Build System",
"description": "Reproducible builds using makefiles or CI systems allow verification that no modifications, such as vulnerabilities or backdoors, have been introduced during a package's build process",
"category": "code quality",
"type": "downscore"
},
{
"title": "Repository Contains Binary Files",
"description": "When a repository contains binary files it is harder to analyze and assess its functionality and risks",
"category": "code quality",
"type": "downscore"
},
{
"title": "High Ratio of Test Code",
"description": "High quality projects should use tests",
"category": "code quality",
"type": "upscore"
},
{
"title": "Repository has Badges",
"description": "The use of badges indicates that the repository is well maintained",
"category": "code quality",
"type": "upscore"
},
{
"title": "Repository has Some Best Practice Files",
"description": "The repository has files that cover basic operational aspects of the project and this shows an emphasis on best practices",
"category": "code quality",
"type": "upscore"
},
{
"title": "Repository has Topics",
"description": "Configuring topics is an indication that the repository is well maintained",
"category": "activity",
"type": "upscore"
},
{
"title": "Repository Uses CI",
"description": "The use of continuous integration is a sign of good developer practices",
"category": "code quality",
"type": "upscore"
},
{
"title": "High Number of Questionable Code Pattern Warnings",
"description": "This package has a large number of instances of questionable code warnings that is typically associated with coding issues and potential bugs.",
"category": "code quality",
"type": "downscore"
}
]
}