mirror of
https://github.com/status-im/spiff-arena.git
synced 2025-01-11 18:54:25 +00:00
fe4dc14b8d
* updated Dockerfile to try to remove security vulnerabilities w/ burnettk * we require curl for health checks w/ burnettk * try to scan docker image in ci * use Dockerfile from backend w/ burnettk * continue-on-error w/ burnettk * attempt to elevate permissions of snyk w/ burnettk * added snyk security github workflow w/ burnettk * fixed location of constraints w/ burnettk * add in or true for snyk tests w/ burnettk * sent the snyk token w/ burnettk * specify the directory for the sarif file w/ burnettk * updated spiffworkflow-connector-command for snyk issue w/ burnettk * updated sql statements sanitize input * ignore issues for debug_controller and check frontend with snyk w/ burnettk * updated babel and electron for snyk w/ burnettk * some more updates to fix vulnerabilities w/ burnettk * prune repeated deps for frontend builds since * uncomment ci code so it runs again and use node for frontend base image w/ burnettk * fixed backend image name w/ burnettk * pyl w/ burnettk --------- Co-authored-by: jasquat <jasquat@users.noreply.github.com>
20 lines
725 B
Plaintext
20 lines
725 B
Plaintext
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
|
|
version: v1.25.0
|
|
# ignores vulnerabilities until expiry date; change duration by modifying expiry date
|
|
ignore: {}
|
|
patch: {}
|
|
|
|
# when running snyk ignore to ignore issues with "snyk code test"
|
|
# make sure to EXCLUDE the id option. Otherwise a bad file is created.
|
|
#
|
|
# Works:
|
|
# snyk ignore --file-path=src/spiffworkflow_backend/routes/debug_controller.py
|
|
#
|
|
# Des not work:
|
|
# snyk ignore --file-path=src/spiffworkflow_backend/routes/debug_controller.py --id=whatever
|
|
#
|
|
# a single vulnerability cannot be ignored for "snyk code test". Only whole files can be ingored.
|
|
exclude:
|
|
global:
|
|
- src/spiffworkflow_backend/routes/debug_controller.py
|