
Currently nancy is always failed, and we seem to ignore it completely. This reduces the value of having security scanning significantly. Ideally, the underlying issue should be fixed, however it will require long time for external collaboration. This commit is to ignore two known dependency failures. Signed-off-by: Tam Mach <sayboras@yahoo.com>
12 lines
252 B
Plaintext
12 lines
252 B
Plaintext
# Skip for golang/golang.org/x/net@v0.0.0-20200904194848-62affa334b73
|
|
CVE-2018-17848
|
|
CVE-2018-17143
|
|
CVE-2018-17847
|
|
CVE-2018-17142
|
|
CVE-2018-17846
|
|
|
|
# Skip for indirect dependency github.com/coreos/etcd@3.3.13
|
|
CVE-2020-15114
|
|
CVE-2020-15115
|
|
CVE-2020-15136
|