|
1 | 1 | # See repository root `osv-scanner.toml` for instructions and rules for this file.
|
2 | 2 | #
|
3 |
| -# Temporarily ignoring all reported android vulnerabilites with a one month deadline |
4 |
| -# since we plan to examine the vulnerabilites and bootstrap this file with proper |
5 |
| -# ignore reasons (or address by bumping dependencies). |
6 |
| -# |
7 |
| -# Also worth mentioning that we're already using the OWASP Dependency-Check tool |
8 |
| -# for the android code base as of before. |
| 3 | +# The OWASP Dependency-Check tool is also used for vulnerability scanning. |
9 | 4 |
|
10 | 5 | [[IgnoredVulns]]
|
11 | 6 | id = "CVE-2022-45868" # GHSA-22wj-vf5f-wrvj
|
12 |
| -ignoreUntil = 2024-08-02 |
13 |
| -reason = "See top comment" |
| 7 | +ignoreUntil = 2024-11-02 |
| 8 | +reason = "Used by the dependency-check tool and not the app directly." |
14 | 9 |
|
15 | 10 | [[IgnoredVulns]]
|
16 | 11 | id = "CVE-2023-3635" # GHSA-w33c-445m-f8w7
|
17 |
| -ignoreUntil = 2024-08-02 |
18 |
| -reason = "See top comment" |
| 12 | +ignoreUntil = 2024-11-02 |
| 13 | +reason = "We do not use gzip when using okio." |
19 | 14 |
|
20 | 15 | [[IgnoredVulns]]
|
21 | 16 | id = "CVE-2024-29025" # GHSA-5jpm-x58v-624v
|
22 |
| -ignoreUntil = 2024-08-02 |
23 |
| -reason = "See top comment" |
| 17 | +ignoreUntil = 2024-11-02 |
| 18 | +reason = "We do not use netty for http communication." |
24 | 19 |
|
25 | 20 | [[IgnoredVulns]]
|
26 | 21 | id = "CVE-2023-44487" # GHSA-xpw8-rcwv-8f8p
|
27 |
| -ignoreUntil = 2024-08-02 |
28 |
| -reason = "See top comment" |
| 22 | +ignoreUntil = 2024-11-02 |
| 23 | +reason = "No impact on this app since it uses UDS rather than HTTP2." |
29 | 24 |
|
30 | 25 | [[IgnoredVulns]]
|
31 | 26 | id = "CVE-2023-34462" # GHSA-6mjq-h674-j845
|
32 |
| -ignoreUntil = 2024-08-02 |
33 |
| -reason = "See top comment" |
| 27 | +ignoreUntil = 2024-11-02 |
| 28 | +reason = "We do not use netty for http communication." |
34 | 29 |
|
35 | 30 | [[IgnoredVulns]]
|
36 | 31 | id = "CVE-2024-26308" # GHSA-4265-ccf5-phj5
|
37 |
| -ignoreUntil = 2024-08-02 |
38 |
| -reason = "See top comment" |
| 32 | +ignoreUntil = 2024-11-02 |
| 33 | +reason = "Apache commons compress is used by lint and not the app directly." |
39 | 34 |
|
40 | 35 | [[IgnoredVulns]]
|
41 | 36 | id = "CVE-2024-25710" # GHSA-4g9r-vxhx-9pgx
|
42 |
| -ignoreUntil = 2024-08-02 |
43 |
| -reason = "See top comment" |
| 37 | +ignoreUntil = 2024-11-02 |
| 38 | +reason = "Apache commons compress is used by lint and not the app directly." |
44 | 39 |
|
45 | 40 | [[IgnoredVulns]]
|
46 | 41 | id = "CVE-2020-13956" # GHSA-7r82-7xv7-xcpj
|
47 |
| -ignoreUntil = 2024-08-02 |
48 |
| -reason = "See top comment" |
| 42 | +ignoreUntil = 2024-11-02 |
| 43 | +reason = "Apache http client is used by lint and not the app directly." |
49 | 44 |
|
50 | 45 | [[IgnoredVulns]]
|
51 | 46 | id = "CVE-2023-51775" # GHSA-6qvw-249j-h44c
|
52 |
| -ignoreUntil = 2024-08-02 |
53 |
| -reason = "See top comment" |
| 47 | +ignoreUntil = 2024-09-02 |
| 48 | +reason = "Used by the gradle bundler, will be fixed by upgrading the android gradle plugin." |
54 | 49 |
|
55 | 50 | [[IgnoredVulns]]
|
56 | 51 | id = "CVE-2023-31582" # GHSA-7g24-qg88-p43q
|
57 |
| -ignoreUntil = 2024-08-02 |
58 |
| -reason = "See top comment" |
| 52 | +ignoreUntil = 2024-09-02 |
| 53 | +reason = "Used by the gradle bundler, will be fixed by upgrading the android gradle plugin." |
59 | 54 |
|
60 | 55 | [[IgnoredVulns]]
|
61 | 56 | id = "GHSA-jgvc-jfgh-rjvv"
|
62 |
| -ignoreUntil = 2024-08-02 |
63 |
| -reason = "See top comment" |
| 57 | +ignoreUntil = 2024-09-02 |
| 58 | +reason = "Used by the gradle bundler, will be fixed by upgrading the android gradle plugin." |
64 | 59 |
|
65 | 60 | [[IgnoredVulns]]
|
66 | 61 | id = "CVE-2022-24329" # GHSA-2qp4-g3q3-f92w
|
67 |
| -ignoreUntil = 2024-08-02 |
68 |
| -reason = "See top comment" |
| 62 | +ignoreUntil = 2024-11-02 |
| 63 | +reason = "This CVE only affect Multiplatform Gradle Projects, which this project is not." |
69 | 64 |
|
70 | 65 | [[PackageOverrides]]
|
71 | 66 | name = "org.bouncycastle:bcprov-jdk15on"
|
72 | 67 | ecosystem = "Maven"
|
73 | 68 | ignore = true
|
74 |
| -effectiveUntil = 2024-08-02 |
75 |
| -reason = "See top comment" |
| 69 | +effectiveUntil = 2024-11-02 |
| 70 | +reason = "Used by lint and the dependency-check tool and not the app directly." |
76 | 71 |
|
77 | 72 | [[PackageOverrides]]
|
78 | 73 | name = "org.bouncycastle:bcprov-jdk18on"
|
79 | 74 | ecosystem = "Maven"
|
80 | 75 | ignore = true
|
81 |
| -effectiveUntil = 2024-08-02 |
82 |
| -reason = "See top comment" |
| 76 | +effectiveUntil = 2024-11-02 |
| 77 | +reason = "Used by lint and the dependency-check tool and not the app directly." |
83 | 78 |
|
84 | 79 | [[PackageOverrides]]
|
85 | 80 | name = "org.bouncycastle:bcpkix-jdk18on"
|
86 | 81 | ecosystem = "Maven"
|
87 | 82 | ignore = true
|
88 |
| -effectiveUntil = 2024-08-02 |
89 |
| -reason = "See top comment" |
| 83 | +effectiveUntil = 2024-11-02 |
| 84 | +reason = "Used by lint and the dependency-check tool and not the app directly." |
0 commit comments