Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Unticketed] Ignore vulnerability for issue fixed in upcoming Python release #3422

Merged
merged 1 commit into from
Jan 7, 2025

Conversation

chouinar
Copy link
Collaborator

@chouinar chouinar commented Jan 7, 2025

Time to review: 1 mins

Changes proposed

Ignore vulnerability https://nvd.nist.gov/vuln/detail/CVE-2024-12254

Context for reviewers

Grype is saying it wants us to upgrade to python 3.14a which releases in October and is not yet prod ready

The fix is also in 3.13, but not yet released (should be February)

@chouinar chouinar requested a review from coilysiren January 7, 2025 15:34
@chouinar chouinar requested a review from mdragon as a code owner January 7, 2025 15:34
@chouinar chouinar merged commit 671dcf0 into main Jan 7, 2025
15 checks passed
@chouinar chouinar deleted the chouinar/python-grype branch January 7, 2025 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants