Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

Patch

com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer 20211018.1

Back to all
Package Version

com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer 20211018.1

Package Version Scores

Overall
0
/10
Security
4
Activity
4
Popularity
7
Quality
6
Quality
Pull Requests from Bots
Pull requests from bot accounts indicate that the project is using automation for development tasks.
Quality
Pull Requests from Bots
Pull requests from bot accounts indicate that the project is using automation for development tasks.

Endor Patches

Patch Name
CVEs fixed
Lines of Code Changed
670eb3f20c57ff79939cf015
CVEs Fixed
C
1
H
0
+40
-31

Get Your First 3 Patches Free

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

References

Basic Information

Ecosystem
Release Date
October 22, 2024
LINES OF CODE CHANGED
+40
-31
-
on latest patch
License
Patch Available

Get Your First 3 Patches Free

Secure your app without upgrading.
Fix Without Upgrading
{
"items": [
{
"title": "No Recent Commit Activity",
"description": "Lack of recent commit activity indicates that the project is not very active",
"category": "activity",
"type": "downscore"
},
{
"title": "Recent Issue Activity",
"description": "Recent issue activity indicates that the project is in active development",
"category": "activity",
"type": "upscore"
},
{
"title": "High Ratio of New Issues",
"description": "Significantly more issues being created than closed indicates that the project may not be maintained",
"category": "activity",
"type": "downscore"
},
{
"title": "High Ratio of Issues Created by External Contributors",
"description": "A high ratio of issues opened by external contributors indicates that the project is active",
"category": "activity",
"type": "upscore"
},
{
"title": "No Merged Pull Requests",
"description": "Lack of merged pull requests indicates that the project may not be maintained",
"category": "activity",
"type": "downscore"
},
{
"title": "Pull Requests Have Labels",
"description": "Attaching labels to pull requests helps organize the development activity in the project",
"category": "code quality",
"type": "upscore"
},
{
"title": "Pull Requests from Bots",
"description": "Pull requests from bot accounts indicate that the project is using automation for development tasks",
"category": "code quality",
"type": "upscore"
},
{
"title": "Pull Requests From Dependency Management Bots",
"description": "Pull requests from dependency management bot accounts indicate that the project is using automation to keep its dependencies up to date",
"category": "code quality",
"type": "upscore"
},
{
"title": "Limited Activity From Corporate Accounts",
"description": "Lack of activity from corporate affiliated accounts indicates that the project may not have reliable backing and support",
"category": "activity",
"type": "downscore"
},
{
"title": "Activity From Bot Accounts",
"description": "Activity from bot accounts shows that the project is using automation for some development tasks",
"category": "code quality",
"type": "upscore"
},
{
"title": "First Major Release Milestone Achieved",
"description": "The repository has reached 1.0 release status, this is a sign of maturity",
"category": "code quality",
"type": "upscore"
},
{
"title": "No Release Activity",
"description": "The repository does not have any recent releases and this could mean that it is not actively maintained",
"category": "activity",
"type": "downscore"
},
{
"title": "First Major Version Milestone Achieved",
"description": "The package has reached version 1.0.0, this is a sign of maturity",
"category": "code quality",
"type": "upscore"
},
{
"title": "No Version Activity",
"description": "The package does not have any recent version creation and this could mean that it is not actively maintained",
"category": "activity",
"type": "downscore"
},
{
"title": "Organization Repository",
"description": "When a repository belongs to an organization there is a lower risk of it getting abandoned in the future",
"category": "activity",
"type": "upscore"
},
{
"title": "Unfixed High Severity Vulnerabilities",
"description": "Unfixed high severity vulnerabilities discovered in a repository indicate an elevated security risk. Analysis only considers vulnerabilities associated with this repository and not its dependencies. Vulnerability information is based on OSV.dev data and Endor's vulnerability database",
"category": "security",
"type": "downscore"
},
{
"title": "Has Stars",
"description": "Having some stars indicates interest in the project. ",
"category": "popularity",
"type": "upscore"
},
{
"title": "Has Forks",
"description": "Having some forks shows an interest in the project",
"category": "popularity",
"type": "neutral"
},
{
"title": "Has Subscribers",
"description": "Having subscribers indicates interest in the project",
"category": "popularity",
"type": "upscore"
},
{
"title": "Comments in Issues",
"description": "A high amount of comment activity in issues shows that there is engagement with the project",
"category": "activity",
"type": "upscore"
},
{
"title": "Repository has Documentation",
"description": "Documentation makes a package easier to understand and use",
"category": "code quality",
"type": "upscore"
},
{
"title": "No Automated Build System",
"description": "Reproducible builds using makefiles or CI systems allow verification that no modifications, such as vulnerabilities or backdoors, have been introduced during a package's build process",
"category": "code quality",
"type": "downscore"
},
{
"title": "High Ratio of Test Code",
"description": "High quality projects should use tests",
"category": "code quality",
"type": "upscore"
},
{
"title": "Repository has Badges",
"description": "The use of badges indicates that the repository is well maintained",
"category": "code quality",
"type": "upscore"
},
{
"title": "Repository Uses GitHub Templates",
"description": "Using GitHub templates to manage issues shows that the development work in the repository is well organized",
"category": "code quality",
"type": "upscore"
},
{
"title": "Repository has Some Best Practice Files",
"description": "The repository has files that cover basic operational aspects of the project and this shows an emphasis on best practices",
"category": "code quality",
"type": "upscore"
},
{
"title": "Multiple Licenses",
"description": "Repositories with multiple licenses require extra effort to determine their exact license status",
"category": "code quality",
"type": "downscore"
},
{
"title": "No Package License",
"description": "Packages without license information can create operational risk",
"category": "code quality",
"type": "downscore"
}
]
}