-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathosv-scanner.toml
More file actions
15 lines (13 loc) · 1.14 KB
/
Copy pathosv-scanner.toml
File metadata and controls
15 lines (13 loc) · 1.14 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
# osv-scanner suppressions for advisories without an available fix.
#
# Mirrors the inline --ignore-vuln list passed to pip-audit in
# .github/workflows/pr-checks.yml so both scanners stay in sync. pip-audit
# accepts ignores as CLI flags; osv-scanner only reads them from this TOML.
# When an advisory is fixed upstream, drop the entry here AND remove the
# matching pip-audit flag in the same PR.
[[IgnoredVulns]]
id = "CVE-2026-49265"
reason = "oauthlib 3.3.1 PKCE timing side channel in the server-side code_challenge check, which coder-eval never runs (oauthlib is transitive via azure-monitor-opentelemetry-exporter -> msrest -> requests-oauthlib). The fix, 4.0.0, is a major bump still inside the safe-chain minimum package age; revisit next month."
[[IgnoredVulns]]
id = "GHSA-hj66-6f7g-4r5v"
reason = "CVE-2026-49264: oauthlib 3.3.1 RevocationEndpoint JSONP callback injection (only with enable_jsonp=True), a server-side OAuth endpoint coder-eval never runs (oauthlib is transitive via azure-monitor-opentelemetry-exporter -> msrest -> requests-oauthlib). The fix, 4.0.0, is a major bump still inside the safe-chain minimum package age; revisit next month."