-
Notifications
You must be signed in to change notification settings - Fork 49
/
audit-ci.jsonc
34 lines (34 loc) · 1.51 KB
/
audit-ci.jsonc
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
{
"$schema": "https://github.com/IBM/audit-ci/raw/main/docs/schema.json",
// audit-ci supports reading JSON, JSONC, and JSON5 config files.
// Only use one of ["low": true, "moderate": true, "high": true, "critical": true]
"moderate": true,
"allowlist": [ // NOTE: Please add as much information as possible to any items added to the allowList
// Currently no fixes available for the following
// widdershins>swagger2openapi>oas-validator>ajv
"GHSA-v88g-cgmw-v5xw",
// // @mojaloop/central-services-shared>shins>ejs
"GHSA-phwq-j96m-2c2q",
// // widdershins>swagger2openapi>better-ajv-errors>jsonpointer
"GHSA-282f-qqgm-c34q",
// @mojaloop/central-services-health>@mojaloop/central-services-error-handling>@mojaloop/sdk-standard-components>jsonwebtoken
// @now-ims/hapi-now-auth>jsonwebtoken
"GHSA-hjrf-2m68-5959",
// @mojaloop/central-services-health>@mojaloop/central-services-error-handling>@mojaloop/sdk-standard-components>jsonwebtoken
"GHSA-qwph-4952-7xr6",
// widdershins>markdown-it
"GHSA-6vfc-qv3f-vr6c",
// @mojaloop/central-services-shared>shins>sanitize-html
"GHSA-mjxr-4v3x-q3m4",
// @mojaloop/central-services-shared>shins>sanitize-html
"GHSA-rjqq-98f6-6j3r",
// tap-spec>tap-out>trim
"GHSA-w5p7-h5w8-2hfq",
// widdershins>yargs>yargs-parser
"GHSA-p9pc-299p-vxgp",
// https://github.com/advisories/GHSA-8cf7-32gw-wr33
"GHSA-8cf7-32gw-wr33",
// https://github.com/advisories/GHSA-7fh5-64p2-3v2j
"GHSA-7fh5-64p2-3v2j"
]
}