Skip to content

Commit

Permalink
feat: ignore private-key rule for opensearch
Browse files Browse the repository at this point in the history
  • Loading branch information
cjdcordeiro committed Aug 3, 2023
1 parent 3cf9fb5 commit 779d096
Showing 1 changed file with 16 additions and 1 deletion.
17 changes: 16 additions & 1 deletion oci/charmed-opensearch/.trivyignore
Original file line number Diff line number Diff line change
@@ -1,3 +1,18 @@
# CVEs in upstream

# com.google.guava:guava:30.0-jre (insecure temporary directory creation), used in:
# - opensearch-alerting
# - opensearch-knn
CVE-2023-2976

# io.grpc:grpc-protobuf:1.52.1 (reachable assertion), impacting:
# - performance-analyzer-rca
CVE-2023-1428
CVE-2023-32731

# io.grpc:grpc-protobuf:1.52.1 (sensitive information disclosure) impacting:
# - performance-analyzer-rca
CVE-2023-32731

# Ignore these rules
# Due to a demo scripts that uses some harmless test keys
private-key

0 comments on commit 779d096

Please sign in to comment.