You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When using osv-scanner configuration toml, ignored vulnerabilities are honoured by the github action, but ignored packages are not. This configuration works when running the osv-scanner tool locally, so I believe this may be an issue with the action.
Scorecard respects that configuration it at HEAD, but not at v5.0.0 which is what v2.4.0 of this action uses. So this is likely something that was fixed/introduced in an update to osv-scanner which hasn't made it here yet.
When using osv-scanner configuration toml, ignored vulnerabilities are honoured by the github action, but ignored packages are not. This configuration works when running the osv-scanner tool locally, so I believe this may be an issue with the action.
Example repo here
The text was updated successfully, but these errors were encountered: