From 44f0459a863fe299ebdcf9e917d5bc6bbb4d3969 Mon Sep 17 00:00:00 2001 From: Ambika Nair Date: Fri, 9 Jun 2023 10:54:44 +0530 Subject: [PATCH] Ignore nancy issue for June internal patch release Signed-off-by: Ambika Nair --- .nancy-ignore | 1 + 1 file changed, 1 insertion(+) diff --git a/.nancy-ignore b/.nancy-ignore index ebd9e90e..6329c3b9 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1,3 +1,4 @@ CVE-2020-8561 ## CWE-610: Externally Controlled Reference to a Resource in Another Sphere CVE-2021-25740 ## CWE-610: Externally Controlled Reference to a Resource in Another Sphere sonatype-2022-6522 ## 1 non-CVE vuln [pkg:golang/k8s.io/apiserver@v0.26.3] +CVE-2021-25749 ## Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.Fix not available in community till now.