🔒 [IBM OSPO Security Notification] — IBM/JSONata4Java
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only —
they will never trigger warnings or archiving.
💡 Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings → Advanced Security → Dependabot security updates → Enable.
📖 New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: (no direct admin collaborators assigned to this repo — please add an admin to receive security notifications)
Dependabot Alerts
No open Dependabot alerts.
Code Scanning Alerts
| Severity |
Rule |
Tool |
Deadline |
| 🟡 medium |
java/implicit-cast-in-compound-assignment |
CodeQL |
2026-12-09 |
Secret Scanning Alerts
No open secret scanning alerts.
🔒 [IBM OSPO Security Notification] — IBM/JSONata4Java
Attention: (no direct admin collaborators assigned to this repo — please add an admin to receive security notifications)
Dependabot Alerts
No open Dependabot alerts.
Code Scanning Alerts
Secret Scanning Alerts
No open secret scanning alerts.