Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ignore sinatra vulnerability #2314

Merged
merged 1 commit into from
Nov 4, 2024
Merged

Ignore sinatra vulnerability #2314

merged 1 commit into from
Nov 4, 2024

Conversation

jdettmannnava
Copy link
Contributor

🎫 Ticket

No ticket

🛠 Changes

Ignoring CVE-2024-2151 added to bundle audit in dpc-portal Dockerfile

ℹ️ Context

CVE-2024-2151 is a security error in Sinatra that does not have a fix. As we use Sinatra internally for testing and as a mock CPI API Gateway (whose port is not exposed to the public internet), ignoring the warning for now seems permissible.

DPC-4359 removes the ignore flag when a fix becomes available.

🧪 Validation

Portal builds and passes CI.

@jdettmannnava jdettmannnava merged commit 13bc4d2 into main Nov 4, 2024
8 checks passed
@jdettmannnava jdettmannnava deleted the jd/sinatra-security branch November 4, 2024 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants