Skip to content

Commit b1c7610

Browse files
committed
ignore an unrelated CVE that nancy complains about
Signed-off-by: Ryan Richard <richardry@vmware.com>
1 parent 26da472 commit b1c7610

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

pipelines/pull-requests/pipeline.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -660,6 +660,12 @@ jobs:
660660
# See https://ossindex.sonatype.org/vulnerability/CVE-2026-24051?component-type=golang&component-name=go.opentelemetry.io%2Fotel%2Fsdk&utm_source=nancy-client&utm_medium=integration&utm_content=1.2.0
661661
CVE-2026-24051 until=2026-06-04
662662
663+
# CVE-2026-56860 is "net/url: avoid quadratic complexity in resolvePath" which is in the Go std lib,
664+
# but nancy also detects it in golang.org/x/net@v0.57.0. If it is in there, we are not using it
665+
# for url paths. We only use golang.org/x/net for some tests. Also, there is currently no newer version
666+
# available, so we can't upgrade it at the moment.
667+
CVE-2026-56860 until=2026-10-17
668+
663669
EOF
664670
665671
cat pinniped-modules/modules.json | nancy sleuth \

0 commit comments

Comments
 (0)