mirror of
https://github.com/kovidgoyal/kitty.git
synced 2026-05-13 08:26:56 +00:00
Ignore dependency CVEs against unreleased versions of deps
This commit is contained in:
parent
81c3fa71a0
commit
c57305addc
1 changed files with 3 additions and 0 deletions
3
.github/workflows/ci.py
vendored
3
.github/workflows/ci.py
vendored
|
|
@ -225,8 +225,11 @@ IGNORED_DEPENDENCY_CVES = [
|
|||
'CVE-2025-12781',
|
||||
'CVE-2025-11468',
|
||||
'CVE-2026-2297',
|
||||
'CVE-2026-3644',
|
||||
'CVE-2026-4224',
|
||||
# github.com/nwaples/rardecode/v2
|
||||
'CVE-2025-11579', # rardecode is version 2.2.1, not vulnerable
|
||||
'CVE-2026-2673', # openssl fix not released
|
||||
]
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue