Ignore CVE for openssl with a fix that has not yet been released

This commit is contained in:
Kovid Goyal 2026-08-21 10:53:01 +05:30
parent d805e28aad
commit a8dee8f0cd
No known key found for this signature in database
GPG key ID: 06BC317B515ACE7C

View file

@ -289,6 +289,7 @@ IGNORED_DEPENDENCY_CVES = [
# github.com/nwaples/rardecode/v2
'CVE-2025-11579', # rardecode is version 2.2.1, not vulnerable
'CVE-2026-2673', # openssl fix not released
'CVE-2026-14456', # openssl fix not released
]