diff --git a/.release/security-scan.hcl b/.release/security-scan.hcl index f9bf3e974f..257a2954a2 100644 --- a/.release/security-scan.hcl +++ b/.release/security-scan.hcl @@ -33,9 +33,12 @@ binary { suppress { vulnerabilites = [ # NET-8174 (2024-02-20): Chart YAML path traversal (not impacted) - "GHSA-v53g-5gjp-272r", # alias CVE-2024-25620 + "GHSA-v53g-5gjp-272r", + "GO-2024-2554", # alias + "CVE-2024-25620", # alias # NET-8174 (2024-02-26): Missing YAML Content Leads To Panic (requires malicious plugin) - "GHSA-r53h-jv2g-vpx6", # alias CVE-2024-26147 + "GHSA-r53h-jv2g-vpx6", + "CVE-2024-26147", # alias ] } } diff --git a/scan.hcl b/scan.hcl index a8bbcda1a4..402f81f950 100644 --- a/scan.hcl +++ b/scan.hcl @@ -33,9 +33,12 @@ repository { ] vulnerabilites = [ # NET-8174 (2024-02-20): Chart YAML path traversal (not impacted) - "GHSA-v53g-5gjp-272r", # alias CVE-2024-25620 + "GHSA-v53g-5gjp-272r", + "GO-2024-2554", # alias + "CVE-2024-25620", # alias # NET-8174 (2024-02-26): Missing YAML Content Leads To Panic (requires malicious plugin) - "GHSA-r53h-jv2g-vpx6", # alias CVE-2024-26147 + "GHSA-r53h-jv2g-vpx6", + "CVE-2024-26147", # alias ] } }