diff --git a/data/reports/GO-2022-1180.yaml b/data/reports/GO-2022-1180.yaml index fe395734..64e95a5b 100644 --- a/data/reports/GO-2022-1180.yaml +++ b/data/reports/GO-2022-1180.yaml @@ -3,7 +3,7 @@ modules: versions: - introduced: 1.8.3 fixed: 1.8.5 - vulnerable_at: 1.8.4 + vulnerable_at: 1.8.5-0.20221217180442-ef63302dc479 packages: - package: github.com/kyverno/kyverno/pkg/engine symbols: @@ -12,6 +12,7 @@ modules: - imageVerifier.verifyAttestors - imageVerifier.verifyAttestorSet - imageVerifier.verifyImage + skip_fix: 'TODO: revisit this reason (undefined: gojmespath.NotFoundError)' description: | `verifyImages` rules can be bypassed by a malicious proxy/registry. cves: