Skip to content

Commit

Permalink
Merge pull request #5024 from oasisprotocol/ptrus/internal/nancy-ignore
Browse files Browse the repository at this point in the history
 go: Ignore CVE-2022-44797 until tendermint uses newer btcd
  • Loading branch information
ptrus authored Nov 8, 2022
2 parents c3243ac + 53e8a0c commit af58921
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 1 deletion.
1 change: 1 addition & 0 deletions .changelog/5024.internal.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
go: Ignore CVE-2022-44797 until tendermint uses newer btcd
2 changes: 1 addition & 1 deletion go/.nancy-ignore
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
CVE-2022-30591 # quic-go resource exhaustion through 0.27.0, 0.27.1 imported, false positive?
sonatype-2022-3945 # remove after upgrade to go-libp2p 0.21.0
CVE-2022-44797 # remove once tendermint uses btcd above or 0.23.2

0 comments on commit af58921

Please sign in to comment.