Skip to content

Conversation

@f-moya
Copy link
Contributor

@f-moya f-moya commented Apr 26, 2021

bundler-audit has a built in option to ignore certain advisories. This is useful under certain scenarios:

  • Manual patches.
  • None precise advisories.

The necessity for this came from the following advisory.
Screen Shot 2021-04-26 at 20 05 08
GHSA-qh4w-7pw3-p4rp

Where actually bson ~> 1.12.3 has a patch in it for this.
mongodb/bson-ruby@976da32#commitcomment-11529744
qltysh-archive/mongo-ruby-driver@bb544c2

So it became of interest to ignore this particular advisory. This work adds that possibility, like follows.

# .codeclimate.yml
plugins:
  bunlder-audit:
    enabled: true
    config:
      ignore:
        - CVE-xxxx-xxxx

Copy link
Contributor

@noelia-lencina noelia-lencina left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice ⭐ Would it be good to add this to the README?

@f-moya
Copy link
Contributor Author

f-moya commented Apr 27, 2021

@noelia-lencina Nice suggestion, thank you. Done.

@f-moya f-moya merged commit 1b92ca6 into master Apr 27, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants