Skip to content

Commit

Permalink
Merge pull request backstage#7990 from backstage/freben/tar2
Browse files Browse the repository at this point in the history
add snyk ignores for the node-gyp tar vuln
  • Loading branch information
freben authored Nov 11, 2021
2 parents 01a0a39 + 9010cdc commit 333e3c2
Show file tree
Hide file tree
Showing 3 changed files with 141 additions and 0 deletions.
47 changes: 47 additions & 0 deletions packages/backend-test-utils/.snyk
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.22.1
# ignores vulnerabilities until expiry date; change duration by modifying expiry date
ignore:
SNYK-JS-TAR-1579155:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1579152:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1579147:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536758:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536531:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536528:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
patch: {}
47 changes: 47 additions & 0 deletions packages/backend/.snyk
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.22.1
# ignores vulnerabilities until expiry date; change duration by modifying expiry date
ignore:
SNYK-JS-TAR-1579155:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1579152:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1579147:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536758:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536531:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536528:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
patch: {}
47 changes: 47 additions & 0 deletions plugins/catalog-backend/.snyk
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.22.1
# ignores vulnerabilities until expiry date; change duration by modifying expiry date
ignore:
SNYK-JS-TAR-1579155:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1579152:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1579147:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536758:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536531:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
SNYK-JS-TAR-1536528:
- 'sqlite3 > node-gyp > tar':
reason: >-
The only usage is via node-gyp; there is no unpacking of untrusted tar
files
expires: 2022-11-11T14:30:05.581Z
created: 2021-11-11T14:30:05.582Z
patch: {}

0 comments on commit 333e3c2

Please sign in to comment.