Skip to content

Commit

Permalink
grype: Ignore CVE-2025-0665
Browse files Browse the repository at this point in the history
Ignore the CVE-2025-0665 vulnerability, since it's a libcurl one, and
the Dangerzone container does not make network calls. Also, it seems
that Debian Bookworm is not affected.
  • Loading branch information
apyrgio committed Feb 10, 2025
1 parent 88a6b37 commit 856de3f
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions .grype.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -37,3 +37,12 @@ ignore:
# [bookworm] - raptor2 <postponed> (Minor issue, revisit when fixed upstream)
#
- vulnerability: CVE-2024-57823
# CVE-2025-0665
# ==============
#
# Debian tracker: https://security-tracker.debian.org/tracker/CVE-2025-0665
# Verdict: Dangerzone is not affected because the vulnerable code is not
# present in Debian Bookworm. Also, libcurl is an HTTP client, and the
# Dangerzone container does not make any network calls.
- vulnerability: CVE-2025-0665

0 comments on commit 856de3f

Please sign in to comment.