Skip to content

Commit

Permalink
Merge pull request #4119 from zendesk/grosser/ignre
Browse files Browse the repository at this point in the history
document bundler audit ignores
  • Loading branch information
grosser authored Oct 14, 2024
2 parents 982fdc1 + 41e8274 commit 21df496
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 1 deletion.
4 changes: 4 additions & 0 deletions .bundler-audit.yml
Original file line number Diff line number Diff line change
@@ -1,2 +1,6 @@
# ignores for `rake bundle_audit`
# - 1 ignore per line
# - leave a comment why we can safely ignore it and where to find more details
# - leave file with `ignore: []` if ignore list is empty
ignore:
- CVE-2024-6484 # ignore until a patch is available https://github.com/advisories/GHSA-9mvj-f7w8-pvh2
2 changes: 1 addition & 1 deletion Rakefile
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ end

desc 'Scan for gem vulnerabilities'
task :bundle_audit do
sh "bundle-audit check --update --ignore=CVE-2024-6484"
sh "bundle-audit check --update" # manage ignores in .bundler-audit.yml
end

desc "Run rubocop"
Expand Down

0 comments on commit 21df496

Please sign in to comment.