mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
build(deps): re-suppress GHSA-h7x2-h6g9-p789 in osv-scan, mlflow still has no fixed release
The 2026-09-14 ignoreUntil on the mlflow SSRF advisory expired today, so osv-scan on any PR against main now fails with 'unused ignores: GHSA-h7x2-h6g9-p789' plus the same vulnerability listed as unfiltered (PYSEC-2026-3865 / GHSA-h7x2-h6g9-p789, mlflow 3.15.0, no fixed version). mlflow 3.16.0 (2026-09-04) and master still store the gateway secret api_base unvalidated, so there is nothing safe to bump to in the lockfile. Re-dates ignoreUntil to 2026-10-14 and records why 3.16.0 does not count as a fix, mirroring the same change already merged into litellm_internal_staging via #41036. Co-authored-by: Krrish Dholakia <krrish-berri-2@users.noreply.github.com>
This commit is contained in:
parent
30f33a949b
commit
bc09e549b6
1 changed files with 2 additions and 2 deletions
|
|
@ -5,5 +5,5 @@ reason = "diskcache has no fixed release published; remove this entry once one e
|
|||
|
||||
[[IgnoredVulns]]
|
||||
id = "GHSA-h7x2-h6g9-p789"
|
||||
ignoreUntil = 2026-09-14
|
||||
reason = "mlflow has no fixed release published; remove this entry once one exists"
|
||||
ignoreUntil = 2026-10-14
|
||||
reason = "mlflow has no fixed release published (3.16.0, 2026-09-04, and master still store gateway secret api_base unvalidated); remove this entry once one exists"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue