allow to ignore vulnerabilities by sonatype id or cve id #5
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
this patch improves the ignore-id parameter to allow setting CVE ids too in addition to the Sonatype ID.
Furthermore the documentation is updated that "id" means the Sonatype id of a vulnerability.
As a lot of other scanners accept CVE ids for whitelisting (even other scanner using Sonatype OSSIndex for other languages) this functionality was added here too. The old implementation was misleading as it was not documented that the id to ignore is not the wildly used and everywhere (throughout the internet) documented CVE id but the proprietary Sonatype one. The default output of ossaudit was not showing the Sonatype ID too, only the CVE (within the title field - if available)
Thanks,
S. Seide