Skip to content

Commit 8fe8e9e

Browse files
[tmp] Revert "Add vulnerability ignore rules"
This reverts commit d7bd126.
1 parent 7cd56ee commit 8fe8e9e

File tree

1 file changed

+0
-12
lines changed

1 file changed

+0
-12
lines changed

WORKSPACE.yaml

Lines changed: 0 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -33,18 +33,6 @@ provenance:
3333
slsa: true
3434
sbom:
3535
enabled: true
36-
ignoreVulnerabilities:
37-
- vulnerability: GHSA-fx4w-v43j-vc45
38-
reason: |
39-
This vulnerability in TypeORM's findOne / findOneOrFail functions can improperly interpret a crafted JSON object
40-
and concatenate it into raw SQL, potentially allowing SQL injection attacks.
41-
42-
In Gitpod’s usage, TypeORM is not exposed to arbitrary user input. For example, DB migrations run preset queries;
43-
the server/bridge code does not hand raw JSON from external sources to findOne. Therefore, there is no path for
44-
injecting malicious JSON into a query, rendering the vulnerability non-exploitable.
45-
- vulnerability: GHSA-2jcg-qqmg-46q6
46-
reason: |
47-
This is a false positive. See https://github.com/browserify/resolve/issues/303
4836
environmentManifest:
4937
- name: "go"
5038
command: ["sh", "-c", "go version | sed s/arm/amd/"]

0 commit comments

Comments
 (0)