-
Notifications
You must be signed in to change notification settings - Fork 9
/
Copy path.safety-policy-install.yml
53 lines (47 loc) · 2.51 KB
/
.safety-policy-install.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
# Safety policy file for packages needed for installation
# For documentation, see https://docs.pyup.io/docs/safety-20-policy-file
# Note: This policy file is used against the versions in minimum-constraints-install.txt.
# Configuration for the 'safety check' command
security:
# Ignore certain severities.
# A number between 0 and 10, with the following significant values:
# - 9: ignore all vulnerabilities except CRITICAL severity
# - 7: ignore all vulnerabilities except CRITICAL & HIGH severity
# - 4: ignore all vulnerabilities except CRITICAL, HIGH & MEDIUM severity
ignore-cvss-severity-below: 0
# Ignore unknown severities.
# Should be set to False.
ignore-cvss-unknown-severity: False
# List of specific vulnerabilities to ignore.
# {id}: # vulnerability ID
# reason: {text} # optional: Reason for ignoring it. Will be reported in the Safety reports
# expires: {date} # optional: Date when this ignore will expire
ignore-vulnerabilities:
54219:
reason: Fixed ansible version is 2.10.0, but we support older ansible versions
54229:
reason: Fixed ansible version is 2.10.5, but we support older ansible versions
54230:
reason: Fixed ansible version is 2.10.5, but we support older ansible versions
54564:
reason: Fixed ansible version is 7.0.0, but we support older ansible versions
63066:
reason: Fixed ansible-core version is 2.15.8, but we support older ansible versions
65511:
reason: Fixed ansible-core version is 2.13.13, but we support older ansible versions
66667:
reason: Fixed ansible-core version is 2.12.0, but we support older ansible versions
66700:
reason: Fixed ansible-core versions are 2.14.14 and 2.16.3, but we support older ansible versions
70612:
reason: Safety issue and CVE do not list a fixed version of Jinja2
70895:
reason: Fixed ansible-core version is 2.15.2, but we support older ansible versions
73302:
reason: Advice to use no_log when reading sensitive variables - not related to any fixes
74221:
reason: Fixed ansible-core version is 2.14.18rc1, but we support older ansible versions
74261:
reason: Fixed ansible-core version is 2.18, but we support older ansible versions
# Continue with exit code 0 when vulnerabilities are found.
continue-on-vulnerability-error: False