From bc09e549b65960a34103d4c83786d0924c2f0290 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Mon, 14 Sep 2026 06:11:26 +0000 Subject: [PATCH] build(deps): re-suppress GHSA-h7x2-h6g9-p789 in osv-scan, mlflow still has no fixed release The 2026-09-14 ignoreUntil on the mlflow SSRF advisory expired today, so osv-scan on any PR against main now fails with 'unused ignores: GHSA-h7x2-h6g9-p789' plus the same vulnerability listed as unfiltered (PYSEC-2026-3865 / GHSA-h7x2-h6g9-p789, mlflow 3.15.0, no fixed version). mlflow 3.16.0 (2026-09-04) and master still store the gateway secret api_base unvalidated, so there is nothing safe to bump to in the lockfile. Re-dates ignoreUntil to 2026-10-14 and records why 3.16.0 does not count as a fix, mirroring the same change already merged into litellm_internal_staging via #41036. Co-authored-by: Krrish Dholakia --- osv-scanner.toml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/osv-scanner.toml b/osv-scanner.toml index 3e070fc8cf7..482254d4da6 100644 --- a/osv-scanner.toml +++ b/osv-scanner.toml @@ -5,5 +5,5 @@ reason = "diskcache has no fixed release published; remove this entry once one e [[IgnoredVulns]] id = "GHSA-h7x2-h6g9-p789" -ignoreUntil = 2026-09-14 -reason = "mlflow has no fixed release published; remove this entry once one exists" +ignoreUntil = 2026-10-14 +reason = "mlflow has no fixed release published (3.16.0, 2026-09-04, and master still store gateway secret api_base unvalidated); remove this entry once one exists"