build(deps): re-suppress GHSA-h7x2-h6g9-p789 in osv-scan, mlflow still has no fixed release

The 2026-09-14 ignoreUntil on the mlflow SSRF advisory expired today, so
osv-scan on any PR against main now fails with 'unused ignores:
GHSA-h7x2-h6g9-p789' plus the same vulnerability listed as unfiltered
(PYSEC-2026-3865 / GHSA-h7x2-h6g9-p789, mlflow 3.15.0, no fixed
version). mlflow 3.16.0 (2026-09-04) and master still store the
gateway secret api_base unvalidated, so there is nothing safe to bump
to in the lockfile.

Re-dates ignoreUntil to 2026-10-14 and records why 3.16.0 does not
count as a fix, mirroring the same change already merged into
litellm_internal_staging via #41036.

Co-authored-by: Krrish Dholakia <krrish-berri-2@users.noreply.github.com>
This commit is contained in:
Cursor Agent 2026-09-14 06:11:26 +00:00
parent 30f33a949b
commit bc09e549b6
No known key found for this signature in database

View file

@ -5,5 +5,5 @@ reason = "diskcache has no fixed release published; remove this entry once one e
[[IgnoredVulns]]
id = "GHSA-h7x2-h6g9-p789"
ignoreUntil = 2026-09-14
reason = "mlflow has no fixed release published; remove this entry once one exists"
ignoreUntil = 2026-10-14
reason = "mlflow has no fixed release published (3.16.0, 2026-09-04, and master still store gateway secret api_base unvalidated); remove this entry once one exists"