{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":593690184,"defaultBranch":"main","name":"fpf-misc-resources","ownerLogin":"freedomofpress","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2023-01-26T16:15:05.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/5388147?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1716479780.0","currentOid":""},"activityList":{"items":[{"before":null,"after":"02b247d3a480697a4ea0a8f92b12d5818f27f3d0","ref":"refs/heads/CVE-2024-35195","pushedAt":"2024-05-23T15:56:20.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"},"commit":{"message":"Ignore CVE-2024-35195\n\nWe don't use requests with verify=False.","shortMessageHtmlLink":"Ignore CVE-2024-35195"}},{"before":"ab0c3c649817ee4257bc1934aca882f266d19f33","after":"e8b4c47bc27fd90ce5da3f826043278bccb19432","ref":"refs/heads/main","pushedAt":"2024-05-20T18:03:35.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"eloquence","name":"Erik Moeller","path":"/eloquence","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/213636?s=80&v=4"},"commit":{"message":"Merge pull request #46 from freedomofpress/CVE-2019-8341\n\nIgnore bogus CVE-2019-8341","shortMessageHtmlLink":"Merge pull request #46 from freedomofpress/CVE-2019-8341"}},{"before":null,"after":"ff9000a0732f4a27409239216ae69f63fe39ce32","ref":"refs/heads/CVE-2019-8341","pushedAt":"2024-05-20T16:14:38.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"},"commit":{"message":"Ignore bogus CVE-2019-8341\n\nTo quote a jinja2 maintainer: \"This CVE is a bad joke\"[1].\n\nWe don't use the vulnerable functions anyways.\n\n[1] https://bugzilla.redhat.com/show_bug.cgi?id=1677653#c4","shortMessageHtmlLink":"Ignore bogus CVE-2019-8341"}},{"before":"2276924ce78db4955f827427c9861a6f088dfa5d","after":null,"ref":"refs/heads/silence-jinja-70612","pushedAt":"2024-05-16T15:38:04.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"harrislapiroff","name":"Harris Bard Lapiroff","path":"/harrislapiroff","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/296631?s=80&v=4"}},{"before":"4248bd55285bcd3b58e72a01d67487f65805ee29","after":"ab0c3c649817ee4257bc1934aca882f266d19f33","ref":"refs/heads/main","pushedAt":"2024-05-16T15:38:01.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"harrislapiroff","name":"Harris Bard Lapiroff","path":"/harrislapiroff","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/296631?s=80&v=4"},"commit":{"message":"Merge pull request #45 from freedomofpress/silence-jinja-70612\n\nIgnore vulnerability in Jinja2","shortMessageHtmlLink":"Merge pull request #45 from freedomofpress/silence-jinja-70612"}},{"before":null,"after":"2276924ce78db4955f827427c9861a6f088dfa5d","ref":"refs/heads/silence-jinja-70612","pushedAt":"2024-05-16T15:29:56.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"SaptakS","name":"Saptak Sengupta","path":"/SaptakS","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/9530293?s=80&v=4"},"commit":{"message":"Ignore vulnerability in Jinja2\n\nAs mentioned in https://data.safetycli.com/v/70612/eda/, the maintainers\nbelieve that this is not a vulnerability. The vulnerability targets\nall versions of Jinja","shortMessageHtmlLink":"Ignore vulnerability in Jinja2"}},{"before":"ab8a5222760bcba9d46e7eb7bc6784005a0e6ae0","after":null,"ref":"refs/heads/ignore-CVE-2019-14890","pushedAt":"2024-05-01T16:00:06.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"}},{"before":null,"after":"ab8a5222760bcba9d46e7eb7bc6784005a0e6ae0","ref":"refs/heads/ignore-CVE-2019-14890","pushedAt":"2024-04-29T14:44:12.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"},"commit":{"message":"Ignore CVE-2019-14890\n\nUsers aren't going to be entering Ansible Tower licenses.","shortMessageHtmlLink":"Ignore CVE-2019-14890"}},{"before":"ce3699adc6e91fa287ba68da842730ad5d2fcaef","after":"4248bd55285bcd3b58e72a01d67487f65805ee29","ref":"refs/heads/main","pushedAt":"2024-04-19T18:03:31.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"rocodes","name":"rocodes","path":"/rocodes","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/22777700?s=80&v=4"},"commit":{"message":"Merge pull request #43 from freedomofpress/pip-idna\n\nSuppress idna and pip alerts","shortMessageHtmlLink":"Merge pull request #43 from freedomofpress/pip-idna"}},{"before":null,"after":"5bd630f2904566f11535ef748fbb37652e7d9307","ref":"refs/heads/pip-idna","pushedAt":"2024-04-18T15:05:52.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"},"commit":{"message":"Suppress idna and pip alerts\n\nCVE-2024-3651 in idna does not affect us because we do not make\nrequests to arbitrary URLs.\n\nFor some reason, safety has re-imported CVE-2018-20225 as 67599,\ndespite it being disputed. Regardless, we don't use `--extra-index-url`.","shortMessageHtmlLink":"Suppress idna and pip alerts"}},{"before":"b0decc5766e50e1aaa3ea83373bf6d7cedc2f02c","after":null,"ref":"refs/heads/cryptography-66777","pushedAt":"2024-03-28T14:04:25.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"SaptakS","name":"Saptak Sengupta","path":"/SaptakS","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/9530293?s=80&v=4"}},{"before":"903363e3aac764165d28d2be3d43179523a290d0","after":"ce3699adc6e91fa287ba68da842730ad5d2fcaef","ref":"refs/heads/main","pushedAt":"2024-03-28T14:04:15.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"SaptakS","name":"Saptak Sengupta","path":"/SaptakS","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/9530293?s=80&v=4"},"commit":{"message":"Merge pull request #42 from freedomofpress/cryptography-66777\n\nIgnore 66777 in pressfreedomtracker.us","shortMessageHtmlLink":"Merge pull request #42 from freedomofpress/cryptography-66777"}},{"before":null,"after":"b0decc5766e50e1aaa3ea83373bf6d7cedc2f02c","ref":"refs/heads/cryptography-66777","pushedAt":"2024-03-27T19:57:09.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"chigby","name":"Cameron Higby-Naquin","path":"/chigby","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/561931?s=80&v=4"},"commit":{"message":"Ignore 66777 in pressfreedomtracker.us","shortMessageHtmlLink":"Ignore 66777 in pressfreedomtracker.us"}},{"before":"58f96bc14d73a86523b5eb0778b3a1ebcdc11aad","after":"903363e3aac764165d28d2be3d43179523a290d0","ref":"refs/heads/main","pushedAt":"2024-03-26T21:32:14.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"zenmonkeykstop","name":"Kevin O'Gorman","path":"/zenmonkeykstop","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/2782952?s=80&v=4"},"commit":{"message":"Merge pull request #41 from freedomofpress/safety-66667\n\nignore Safety 66667 in `ansible-core`","shortMessageHtmlLink":"Merge pull request #41 from freedomofpress/safety-66667"}},{"before":null,"after":"22cd9595d7b42febd89f851a08e25a9f8e57f916","ref":"refs/heads/safety-66667","pushedAt":"2024-03-26T20:07:07.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"cfm","name":"Cory Francis Myers","path":"/cfm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/357435?s=80&v=4"},"commit":{"message":"ignore Safety 66667 in ansible-core\n\nNot exploitable in our production usage.","shortMessageHtmlLink":"ignore Safety 66667 in ansible-core"}},{"before":null,"after":"35fe56cd3040c74d5fd5d17b7c99a025ba2d7271","ref":"refs/heads/silence-cryptography-66777","pushedAt":"2024-03-25T18:38:29.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"SaptakS","name":"Saptak Sengupta","path":"/SaptakS","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/9530293?s=80&v=4"},"commit":{"message":"Ignores vulnerability in cryptography","shortMessageHtmlLink":"Ignores vulnerability in cryptography"}},{"before":"d4791743cac9a8ae20f317c741fdbe7dfce657e7","after":null,"ref":"refs/heads/safety-66777","pushedAt":"2024-03-20T20:57:08.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"}},{"before":"455208877e1641226fb7b55efa920bfc70906268","after":"58f96bc14d73a86523b5eb0778b3a1ebcdc11aad","ref":"refs/heads/main","pushedAt":"2024-03-20T20:57:05.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"},"commit":{"message":"Merge pull request #39 from freedomofpress/safety-66777\n\nchore: ignore Safety 66777 in `cryptography`","shortMessageHtmlLink":"Merge pull request #39 from freedomofpress/safety-66777"}},{"before":null,"after":"d4791743cac9a8ae20f317c741fdbe7dfce657e7","ref":"refs/heads/safety-66777","pushedAt":"2024-03-20T01:22:33.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"cfm","name":"Cory Francis Myers","path":"/cfm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/357435?s=80&v=4"},"commit":{"message":"chore: ignore Safety 66777 in cryptography\n\nNot exploitable in our production usage.","shortMessageHtmlLink":"chore: ignore Safety 66777 in cryptography"}},{"before":"6d35b50a4cd31b02c76b796431745caeb603fe3c","after":"455208877e1641226fb7b55efa920bfc70906268","ref":"refs/heads/main","pushedAt":"2024-03-19T06:59:28.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"SaptakS","name":"Saptak Sengupta","path":"/SaptakS","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/9530293?s=80&v=4"},"commit":{"message":"Merge pull request #38 from freedomofpress/ignore-another-sslyze-related-vuln\n\nIgnores vulnerability in cryptography package","shortMessageHtmlLink":"Merge pull request #38 from freedomofpress/ignore-another-sslyze-rela…"}},{"before":"44cba044e65650361b4a79d940661b6a29bd1d1e","after":null,"ref":"refs/heads/20240318-securedrop","pushedAt":"2024-03-18T20:28:05.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"}},{"before":"c345663cb28cd8297013f0f214521c081c49627b","after":"6d35b50a4cd31b02c76b796431745caeb603fe3c","ref":"refs/heads/main","pushedAt":"2024-03-18T20:28:03.000Z","pushType":"pr_merge","commitsCount":4,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"},"commit":{"message":"Merge pull request #37 from freedomofpress/20240318-securedrop\n\nignore multiple Safety alerts in SecureDrop","shortMessageHtmlLink":"Merge pull request #37 from freedomofpress/20240318-securedrop"}},{"before":null,"after":"fb7d8c32b176834c2aeb1195c5082b818643e654","ref":"refs/heads/ignore-another-sslyze-related-vuln","pushedAt":"2024-03-18T19:31:29.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"chigby","name":"Cameron Higby-Naquin","path":"/chigby","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/561931?s=80&v=4"},"commit":{"message":"Ignores vulnerability in cryptography\n\nAffects version < 42.0.4, which we are currently stuck on until sslyze\nreleases a new version that updates that dependency.","shortMessageHtmlLink":"Ignores vulnerability in cryptography"}},{"before":null,"after":"44cba044e65650361b4a79d940661b6a29bd1d1e","ref":"refs/heads/20240318-securedrop","pushedAt":"2024-03-18T12:31:54.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"cfm","name":"Cory Francis Myers","path":"/cfm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/357435?s=80&v=4"},"commit":{"message":"ignore Safety 66710 in dnspython (development-only)","shortMessageHtmlLink":"ignore Safety 66710 in dnspython (development-only)"}},{"before":"9a77a83b40c1df71b71e994e46c72ffa0ed26e77","after":"c345663cb28cd8297013f0f214521c081c49627b","ref":"refs/heads/main","pushedAt":"2024-03-12T12:53:34.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"SaptakS","name":"Saptak Sengupta","path":"/SaptakS","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/9530293?s=80&v=4"},"commit":{"message":"Merge pull request #36 from freedomofpress/ignore-sslyze-related-vulns-www-projects\n\nIgnore vulnerabilities related to pending `sslyze` update","shortMessageHtmlLink":"Merge pull request #36 from freedomofpress/ignore-sslyze-related-vuln…"}},{"before":null,"after":"ded783af469f020fefcc0b8a62d9a8b9991eae6e","ref":"refs/heads/ignore-sslyze-related-vulns-www-projects","pushedAt":"2024-03-11T20:42:02.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"chigby","name":"Cameron Higby-Naquin","path":"/chigby","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/561931?s=80&v=4"},"commit":{"message":"Ignore vulnerabilities related to pending `sslyze` update\n\nSee related Github posts:\n\n* https://github.com/nabla-c0d3/sslyze/issues/638\n* https://github.com/nabla-c0d3/sslyze/issues/641#issuecomment-1962543838","shortMessageHtmlLink":"Ignore vulnerabilities related to pending sslyze update"}},{"before":"4da7d986da16970626906fd58c59d99d93cf252c","after":null,"ref":"refs/heads/securedrop-20240227","pushedAt":"2024-02-28T23:01:48.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"}},{"before":"0dfcc1db9049152d101a160df3d1e2086ff9b253","after":"9a77a83b40c1df71b71e994e46c72ffa0ed26e77","ref":"refs/heads/main","pushedAt":"2024-02-28T23:01:44.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"},"commit":{"message":"Merge pull request #35 from freedomofpress/securedrop-20240227\n\nignore Safety 65647 in `cryptography`","shortMessageHtmlLink":"Merge pull request #35 from freedomofpress/securedrop-20240227"}},{"before":null,"after":"4da7d986da16970626906fd58c59d99d93cf252c","ref":"refs/heads/securedrop-20240227","pushedAt":"2024-02-27T17:49:01.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"cfm","name":"Cory Francis Myers","path":"/cfm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/357435?s=80&v=4"},"commit":{"message":"ignore Safety 65647 in cryptography\n\nWe do not use the affected X.509 support.","shortMessageHtmlLink":"ignore Safety 65647 in cryptography"}},{"before":"8b21a43eae9cde22c04bb84bea5bafbf498d9f4d","after":null,"ref":"refs/heads/20240221-securedrop","pushedAt":"2024-02-21T21:53:39.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"legoktm","name":"Kunal Mehta","path":"/legoktm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/81392?s=80&v=4"}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAAEUjW9RQA","startCursor":null,"endCursor":null}},"title":"Activity · freedomofpress/fpf-misc-resources"}