Skip to content

Remove SyncPending flag from flock, since it's only used in file_cache.

014da68
Select commit
Loading
Failed to load commit list.
Draft

Network fault tolerance #705

Remove SyncPending flag from flock, since it's only used in file_cache.
014da68
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Code Security Check succeeded Oct 1, 2025 in 3m 4s

Code Security Report

New findings (4)

The Code Security Check detected a total of 4 new findings.

SeverityVulnerability TypeCWEFileData FlowsDetected
LowWeak Hash Strength

CWE-916

block_blob.go:1013

12025-05-16 10:36pm
Vulnerable Code

log.Warn("BlockBlob::ReadToFile : Failed to get MD5 Sum for blob %s", name)

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

 
LowWeak Hash Strength

CWE-916

block_blob.go:1002

12025-05-16 10:36pm
Vulnerable Code

log.Warn("BlockBlob::ReadToFile : Failed to generate MD5 Sum for %s", name)

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

 
LowWeak Hash Strength

CWE-916

block_blob.go:1018

12025-05-16 10:36pm
Vulnerable Code

return errors.New("md5 sum mismatch on download")

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

 
LowWeak Hash Strength

CWE-916

block_blob.go:1017

12025-05-16 10:36pm
Vulnerable Code

log.Err("BlockBlob::ReadToFile : MD5 Sum mismatch %s", name)

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

Resolved findings

No findings were resolved in comparison to the base branch.

Overall findings

The Code Security Check detected a total of 21 findings, 11 of them high severity. More details about the overall state can be found in the Mend Application.


Scan token: b627aff24c894ee7950ab224ac9e5508