fix(security): ignore decompress security vulnerability (#6125)

This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2026-07-07 13:58:15 -04:00
1 parent e381d22200
commit 333d73e334
1 file changed
+2 -1
+2 -1
View File
@@ -24,7 +24,8 @@ verifyDepsBeforeRun: false
# fed user-supplied expressions. Kept in sync with the .circleci SECURITY_AUDIT # fed user-supplied expressions. Kept in sync with the .circleci SECURITY_AUDIT
# job and the root `audit` script. # job and the root `audit` script.
auditConfig: auditConfig:
ignoreGhsas: [] ignoreGhsas:
- GHSA-mp2f-45pm-3cg9 # decompress is called only ever decompresses a hash-pinned, hardcoded archive in a dev-only CLI
allowBuilds: allowBuilds:
'@scarf/scarf': true '@scarf/scarf': true