-
Notifications
You must be signed in to change notification settings - Fork 3
Expand file tree
/
Copy pathosv-scanner.toml
More file actions
15 lines (15 loc) · 862 Bytes
/
Copy pathosv-scanner.toml
File metadata and controls
15 lines (15 loc) · 862 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# OSV-Scanner suppression file — https://google.github.io/osv-scanner/configuration/
#
# Passed via `--config=osv-scanner.toml` by both the weekly scan
# (`.github/workflows/audit.yml`) and the advisory PR scan (`audit-advisory` job
# in `.github/workflows/ci.yml`). It covers `fhir-mapbuilder-validation/pom.xml`
# and `vscode-extension/package-lock.json` in a single pass.
#
# Empty on purpose: nothing is suppressed today. To silence a specific CVE/GHSA
# (false positive, unreachable code path, fix not yet available), add a block —
# and keep the rationale in `CONTRIBUTING.md`:
#
# [[IgnoredVulns]]
# id = "GHSA-xxxx-xxxx-xxxx" # or CVE-YYYY-NNNNN; aliases are matched too
# ignoreUntil = 2026-12-31 # optional revisit date; the entry expires on its own
# reason = "Not exploitable: the vulnerable code path is never reached (see #NNN)."