osv-scanner.toml 1.1 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152
  1. # GHSA-67hx-6x53-jw92
  2. [[PackageOverrides]]
  3. name = "@babel/traverse"
  4. ecosystem = "npm"
  5. ignore = true
  6. reason = "Accepted known vulnerabilities for testing purposes"
  7. # GHSA-67hx-6x53-jw92
  8. [[PackageOverrides]]
  9. name = "babel-traverse"
  10. ecosystem = "npm"
  11. ignore = true
  12. reason = "Accepted known vulnerabilities for testing purposes"
  13. # GHSA-9c47-m6qq-7p4h
  14. [[PackageOverrides]]
  15. name = "json5"
  16. ecosystem = "npm"
  17. ignore = true
  18. reason = "Dependency not critical for security"
  19. # GHSA-7fh5-64p2-3v2j
  20. [[PackageOverrides]]
  21. name = "postcss"
  22. ecosystem = "npm"
  23. ignore = true
  24. reason = "Vulnerabilities do not affect current use case"
  25. # GHSA-gcx4-mw62-g8wm
  26. [[PackageOverrides]]
  27. name = "rollup"
  28. ecosystem = "npm"
  29. ignore = true
  30. reason = "Legacy build tool under controlled environment"
  31. # GHSA-c2qf-rxjj-qqgw
  32. [[PackageOverrides]]
  33. name = "semver"
  34. ecosystem = "npm"
  35. ignore = true
  36. reason = "Version parsing is managed securely"
  37. # GHSA-353f-5xf4-qw67
  38. # GHSA-c24v-8rfc-w8vw
  39. # GHSA-8jhw-289h-jh2g
  40. # GHSA-64vr-g452-qvp3
  41. # GHSA-9cwx-2883-4wfx
  42. [[PackageOverrides]]
  43. name = "vite"
  44. ecosystem = "npm"
  45. ignore = true
  46. reason = "Development server not exposed to untrusted networks"