Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ignore pip and setuptools vulnerabilities on 'jf audit' #388

Open
EytanRhl opened this issue Mar 4, 2025 · 0 comments
Open

Ignore pip and setuptools vulnerabilities on 'jf audit' #388

EytanRhl opened this issue Mar 4, 2025 · 0 comments
Labels
feature request New feature or request

Comments

@EytanRhl
Copy link

EytanRhl commented Mar 4, 2025

Is your feature request related to a problem? Please describe.

When Running 'jf audit' command on an empty python project, there are still vulnerabilities on pip and setuptools, even though the project is empty and does not contain any reference to pip or setuptools.

Describe the solution you'd like to see

'audit' should report vulnerabilities based on what is present on the venv after pulling the dependencies and should ignore pip and setuptools as long as they are not part of the project requirement file.

Describe alternatives you've considered

Another way is to add an option to ignore specific CVE's as vulnerabilities on the scan.

Additional context

TBD

@EytanRhl EytanRhl added the feature request New feature or request label Mar 4, 2025
@shuvadipc shuvadipc transferred this issue from jfrog/jfrog-cli Mar 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature request New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant