From 022f0efcd73335ebbacb9b14a771ebc078a80f16 Mon Sep 17 00:00:00 2001 From: Brad Decker Date: Tue, 25 Jan 2022 14:34:50 -0600 Subject: [PATCH] Update vulnerability ignore list (#13390) --- .circleci/scripts/yarn-audit.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.circleci/scripts/yarn-audit.sh b/.circleci/scripts/yarn-audit.sh index 0f2de7123..30efcf2d7 100755 --- a/.circleci/scripts/yarn-audit.sh +++ b/.circleci/scripts/yarn-audit.sh @@ -7,7 +7,7 @@ set -o pipefail # use `improved-yarn-audit` since that allows for exclude # exclude 1002401 until we remove use of 3Box, 1002581 until we can find a better solution -yarn run improved-yarn-audit --ignore-dev-deps --min-severity moderate --exclude 1002401,1002581,GHSA-93q8-gq69-wqmw,GHSA-257v-vj4p-3w2h +yarn run improved-yarn-audit --ignore-dev-deps --min-severity moderate --exclude 1002401,1002581,GHSA-93q8-gq69-wqmw,GHSA-257v-vj4p-3w2h,GHSA-qrpm-p2h7-hrv2 audit_status="$?" # Use a bitmask to ignore INFO and LOW severity audit results