Skip to content

Commit

Permalink
release: ignore AWS SDK vulnerability for release
Browse files Browse the repository at this point in the history
The reported AWS S3 vulnerability was inherited from the go-getter
module that Packer uses for downloading files from external sources.

This vulnerability only impacts S3 uploads, therefore Packer is not
vulnerable itself as go-getter only downloads such blobs.

Since the change required to fix this advisory would be to bump the AWS
SDK to v2, this being a major change, is not something to do lightly, so
we opted to ignore this advisory for now so it doesn't block upcoming
releases.
  • Loading branch information
lbajolet-hashicorp committed Jan 6, 2025
1 parent 024bf72 commit 783d511
Showing 1 changed file with 10 additions and 0 deletions.
10 changes: 10 additions & 0 deletions .release/security-scan.hcl
Original file line number Diff line number Diff line change
Expand Up @@ -13,4 +13,14 @@ binary {
osv = true
oss_index = true
nvd = false

# Triage items that are _safe_ to ignore here. Note that this list should be
# periodically cleaned up to remove items that are no longer found by the scanner.
triage {
suppress {
vulnerabilities = [
"GO-2022-0635", // github.com/aws/[email protected] TODO(dduzgun-security): remove when deps is resolved
]
}
}
}

0 comments on commit 783d511

Please sign in to comment.