Skip to content

Suppress CVE-2024-8096#21737

Merged
sarahalsmiller merged 1 commit into
mainfrom
Suppress-CVE-2024-8096
Sep 16, 2024
Merged

Suppress CVE-2024-8096#21737
sarahalsmiller merged 1 commit into
mainfrom
Suppress-CVE-2024-8096

Conversation

@sarahalsmiller
Copy link
Copy Markdown
Member

Description

Suppress CVE-2024-8096 because it doesn't have a solution yet.

Testing & Reproduction steps

Links

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

@sarahalsmiller sarahalsmiller requested a review from a team as a code owner September 16, 2024 15:53
@sarahalsmiller sarahalsmiller added pr/no-changelog PR does not need a corresponding .changelog entry pr/no-backport backport/all Apply backports for all active releases per .release/versions.hcl and removed pr/no-backport labels Sep 16, 2024
Copy link
Copy Markdown
Member

@zalimeni zalimeni left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - linking #21729 for back reference since this is a follow-up to that one.

(For posterity: it appears Alpine maintainers have reverted the 8.10 upgrade of curl back to 8.9, causing previously passing security scans to fail)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport/all Apply backports for all active releases per .release/versions.hcl backport/ent/1.18 Changes are backported to 1.18 ent pr/no-changelog PR does not need a corresponding .changelog entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants