Skip to content

Commit

Permalink
Add vulnerabilities to ignore file (#690)
Browse files Browse the repository at this point in the history
Add vulnerabilities to ignore file
  • Loading branch information
chouinar authored Nov 17, 2023
1 parent 9ec395b commit 0caf864
Show file tree
Hide file tree
Showing 2 changed files with 15 additions and 3 deletions.
10 changes: 8 additions & 2 deletions .grype.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,12 @@ ignore:
# https://github.com/anchore/grype/issues/1172
- vulnerability: GHSA-xqr8-7jwr-rhp7
- vulnerability: GHSA-7fh5-64p2-3v2j
# pip vulnerability, need to wait for the Python image to update to 23.x
# https://github.com/docker-library/python/blob/402b993af9ca7a5ee22d8ecccaa6197bfb957bc5/3.12/slim-bookworm/Dockerfile#L137
# pip vulnerability, need to wait for the Python image to update to 23.x
# https://github.com/docker-library/python/blob/402b993af9ca7a5ee22d8ecccaa6197bfb957bc5/3.12/slim-bookworm/Dockerfile#L137
- vulnerability: GHSA-mq26-g339-26xf
# 11/14/2023 - Postgres vulnerabilities in the Debian image
- vulnerability: CVE-2023-39417
- vulnerability: CVE-2023-5869
- vulnerability: CVE-2023-39418
- vulnerability: CVE-2023-5868
- vulnerability: CVE-2023-5870
8 changes: 7 additions & 1 deletion .trivyignore
Original file line number Diff line number Diff line change
Expand Up @@ -7,4 +7,10 @@
# Issue: Why there is a finding and why this is here or not been removed
# Last checked: Date last checked in scans
#The-CVE-or-vuln-id # Remove comment at start of line
CVE-2023-5363
CVE-2023-5363
# 11/14/2023 - Postgres vulnerabilities in the Debian image
CVE-2023-39417
CVE-2023-5869
CVE-2023-39418
CVE-2023-5868
CVE-2023-5870

0 comments on commit 0caf864

Please sign in to comment.