Skip to content

Commit

Permalink
ENG-36521: Updated trivy ignore for open source dependencies
Browse files Browse the repository at this point in the history
  • Loading branch information
laxmanchekka committed Nov 27, 2023
1 parent e8812f2 commit 8180a74
Showing 1 changed file with 13 additions and 4 deletions.
17 changes: 13 additions & 4 deletions .trivyignore
Original file line number Diff line number Diff line change
@@ -1,11 +1,20 @@
# org.yaml:snakeyaml (from upstream opensource shaded dependency. will be taken care during upgrade.)
CVE-2022-1471 exp:2023-09-30
CVE-2022-1471 exp:2023-12-31

# net.minidev:json-smart (from upstream opensource shaded dependency. will be taken care during upgrade.)
CVE-2023-1370 exp:2023-09-30
CVE-2023-1370 exp:2023-12-31

# com.google.guava:guava (from upstream opensource shaded dependency. will be taken care during upgrade.)
CVE-2023-2976 exp:2023-09-30
CVE-2023-2976 exp:2023-12-31

# org.apache.helix:helix-core (from upstream opensource shaded dependency. will be taken care during upgrade.)
CVE-2023-38647 exp:2023-09-30
CVE-2023-38647 exp:2023-12-31

# org.apache.avro:avro (from upstream opensource shaded dependency. will be taken care during upgrade.)
CVE-2023-39410 exp:2023-12-31

# org.apache.zookeeper:zookeeper (from upstream opensource shaded dependency. will be taken care during upgrade.)
CVE-2023-44981 exp:2023-12-31

# io.netty:netty-codec-http2 (from upstream opensource shaded dependency. will be taken care during upgrade.)
GHSA-xpw8-rcwv-8f8p exp:2023-12-31

0 comments on commit 8180a74

Please sign in to comment.