From d87598530a312c2e743adc2f3d5ae544e981e7d6 Mon Sep 17 00:00:00 2001 From: Jaro Hartmann Date: Tue, 18 Jul 2023 15:30:49 +0200 Subject: [PATCH] chore(trivy): suppress false positive for CVE-2023-2976 --- .config/.trivyignore | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.config/.trivyignore b/.config/.trivyignore index 9916cd898b..9102906970 100644 --- a/.config/.trivyignore +++ b/.config/.trivyignore @@ -2,4 +2,7 @@ CVE-2022-42003 # HttpInvokerServiceExporter is not loaded as a bean in the IRS. -CVE-2016-1000027 \ No newline at end of file +CVE-2016-1000027 + +# Vulnerability method not in IRS codebase (Files.createTempDir from guava). https://github.com/google/guava/issues/2575 +CVE-2023-2976 \ No newline at end of file