Skip to content

Commit 6550ee9

Browse files
author
osv-scanner-prune-bot
committed
chore(deps): remove GHSA-v2hh-gcrm-f6hx from osv-scanner.toml
fast-uri upgraded to 3.1.5, vulnerability fixed in 3.1.4 Ticket: HSM-429
1 parent 3d1f975 commit 6550ee9

2 files changed

Lines changed: 4724 additions & 4824 deletions

File tree

osv-scanner.toml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -62,6 +62,3 @@ reason = "tar decompression/parse DoS via unlimited input; transitive via lerna/
6262
id = "GHSA-8x88-c5mf-7j5w"
6363
reason = "tar infinite loop via negative entry size; transitive via lerna/yeoman-generator/swarm-js requiring tar <7.5.18; fix only in tar 7.5.18+ which breaks lerna packDirectory (same constraint as GHSA-8qq5-rm4j-mr97); our usage is archive PACKING only, not extraction"
6464

65-
[[IgnoredVulns]]
66-
id = "GHSA-v2hh-gcrm-f6hx"
67-
reason = "fast-uri host confusion via literal backslash authority (CVE-2026-16221); fixed in 3.1.4 but that release is held for SafeChain. Pinning 3.1.3 clears GHSA-4c8g-83qw-93j6 / CVE-2026-13676. Re-evaluate on 2026-07-26: bump to 3.1.4 and remove this temporary exclusion (security team guidance, WCI-1125)"

0 commit comments

Comments
 (0)