Add ignored_vulnerabilities field on the Project configuration #1271 #1281
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR extends the scancode-config.yml file to selectively ignore vulnerabilities.
The new
ignored_vulnerabilities
field is a list of ignored vulnerabilities, one per line.This can be a a VCID, CVE or any vulnerability alias supported by VulnerableCode.
For example:
For now, the behavior is to ignore these entirely when doing a vulnerability scan.
In the future, this will be enhanced to provide extra details such as a reason why this is
ignored and serve as a proper input to a vulnerability disclosure or VEX report.