Skip to content

Commit 9d673ef

Browse files
Merge pull request #441 from step-security/fix/vulnerabilities
fix: fix both docker vulns and package vulns
2 parents dd471ff + fd1f9bb commit 9d673ef

File tree

2 files changed

+5
-1
lines changed

2 files changed

+5
-1
lines changed

Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM node:lts-alpine@sha256:9bef0ef1e268f60627da9ba7d7605e8831d5b56ad07487d24d1aa386336d1944
1+
FROM node:lts-alpine@sha256:dbcedd8aeab47fbc0f4dd4bffa55b7c3c729a707875968d467aaaea42d6225af
22

33
RUN mkdir -p /var/task/
44

osv-scanner.toml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,7 @@ reason = "Axios URL is not user-controlled"
55
[[IgnoredVulns]]
66
id = "GHSA-952p-6rrq-rcjv"
77
reason = "It is a test dependency"
8+
9+
[[IgnoredVulns]]
10+
id = "GHSA-52f5-9888-hmc6"
11+
reason = "It is dependency used to lint commit messages, hence can be ignored"

0 commit comments

Comments
 (0)