Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add an osv-scanner.toml file to ignore false positive vulnerabilities #2592

Closed
aunovis-heidrich opened this issue Mar 11, 2025 · 0 comments · Fixed by #2593
Closed

Add an osv-scanner.toml file to ignore false positive vulnerabilities #2592

aunovis-heidrich opened this issue Mar 11, 2025 · 0 comments · Fixed by #2593

Comments

@aunovis-heidrich
Copy link
Contributor

The Open Source Vulnerability Scanner, well, scans open source repositories for known vulnerabilities. If you run it on the reqwest repo, it currently finds 74 unfixed vulnerabilities. At second glance, these all stem from npm packages, and from within the wasm_github_fetch example.

However, tools like OSSF Scorecard that use this scanner may not easily expose that second glance. Instead, with default settings, scorecard just reports 74 vulnerabilities, and basically recommends to not use this repo.

This can be circumvented, I believe rather easily, by telling the OSV scanner "don't bother scanning these dependencies here", using an osv-scanner.toml file. Scorecard respects these directives.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant