/
.safety-policy-install.yml
58 lines (53 loc) · 2.79 KB
/
.safety-policy-install.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
# Safety policy file for packages needed for installation
# For documentation, see https://docs.pyup.io/docs/safety-20-policy-file
#
# Generally package vulnerabilites listed in the ignore-vulnerabilities
# list below are there because:
# 1. There is no release that resolves the vulnerability. In this case, there
# should also be an expire entry to remind the pywbem team to recheck
# 2. The required version of a package to resolve the issue is not available
# for all of the python version supported by pywbem. In that case, the
# vulnerability will remain ignored until such time as the versions of
# python that cannot support the required version of the package are no
# longer supported by pywbem.
#
# The way to see python version limitations for package versions
# as defined for pywbem is to filter the file minimum-constraints.txt
# for the package name. Multiple entries for same package name imply
# different minimum versions for different python releases.
# Configuration for the 'safety check' command
security:
# Ignore certain severities.
# A number between 0 and 10, with the following significant values:
# - 9: ignore all vulnerabilities except CRITICAL severity
# - 7: ignore all vulnerabilities except CRITICAL & HIGH severity
# - 4: ignore all vulnerabilities except CRITICAL, HIGH & MEDIUM severity
ignore-cvss-severity-below: 0
# Ignore unknown severities.
# Should be set to False.
ignore-cvss-unknown-severity: False
# List of specific vulnerabilities to ignore.
# {id}: # vulnerability ID
# reason: {text} # optional: Reason for ignoring it. Will be reported in the Safety reports
# expires: {date} # optional: Date when this ignore will expire
ignore-vulnerabilities:
39611:
reason: Fixed PyYAML version 5.4 requires Python>=3.6; full_load method or FullLoader is not used
40291:
reason: Fixed pip version 21.1 requires Python>=3.6 and is used there
42559:
reason: Fixed pip version 21.1 requires Python>=3.6 and is used there
51499:
reason: Fixed wheel version 0.38.1 requires Python>=3.7 and is used there
52365:
reason: Fixed certifi version 2022.12.07 requires Python>=3.6 and is used there
52495:
reason: Fixed setuptools version 65.5.1 requires Python>=3.7 and is used there
58755:
reason: Fixed requests version 2.31.0 requires Python>=3.7 and is used there
59956:
reason: Fixed certifi version 2023.07.22 requires Python>=3.6 and is used there
62044:
reason: Fixed pip version 23.3 requires Python>=3.7 and is used there
# Continue with exit code 0 when vulnerabilities are found.
continue-on-vulnerability-error: False