-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathosv-scanner.toml
More file actions
21 lines (19 loc) · 1.29 KB
/
Copy pathosv-scanner.toml
File metadata and controls
21 lines (19 loc) · 1.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
# OSV Scanner Configuration
# https://google.github.io/osv-scanner/configuration/
[[IgnoredVulns]]
# GHSA-g7r4-m6w7-qqqr: path traversal in esbuild's dev server (--servedir) on
# Windows, affecting esbuild <0.28.1. esbuild is a dev-only transitive dependency
# (via tsup) used solely as a bundler; its dev server is never invoked, so this is
# not exploitable here. Resolves naturally once tsup bumps its esbuild range past
# the affected versions.
id = "GHSA-g7r4-m6w7-qqqr"
reason = "esbuild dev-server path traversal (Windows --servedir only); dev-only transitive dep via tsup, used only as a bundler — dev server never invoked."
[[IgnoredVulns]]
# GHSA-mh99-v99m-4gvg: unbounded brace expansion can exhaust memory when
# attacker-controlled patterns reach brace-expansion directly or through glob.
# The affected v1/v2 copies are dev-only transitive dependencies of Jest's
# reporting and coverage tooling, receive only repository-controlled patterns,
# and are not included in the published package. Remove this exception once
# Jest's dependency tree uses brace-expansion >=5.0.8.
id = "GHSA-mh99-v99m-4gvg"
reason = "brace-expansion DoS requires attacker-controlled glob patterns; affected copies are dev-only Jest reporting/coverage transitives, receive only repository-controlled patterns, and are not shipped."