bovy89
bovy89
gradle version: 6.8 plugin version: ``` id "org.cyclonedx.bom" version "1.3.0" ````
This issue has been resolved in master (see #572), but a new release is required
Similar issue here: https://keycloak.discourse.group/t/refresh-loop-and-refresh-token-error/17503 Disabling the "Enhanced Tracking Protection" on Firefox do not fix the infinite loop
Thanks. I was thinking about a new "allowlist" feature...for example: ``` allowlist > add > - vulnerability name: GHSA-57j2-w4cx-62h2 - comment: fix not available ``` ---> CI pipeline not blocked...
Any update on that? (at least a global allowlist)
Another example of CVE affecting a multitude of projects where a global allowlist would be useful: https://github.com/FasterXML/jackson-databind/issues/3590