Christian Bollmeyer

Results 5 comments of Christian Bollmeyer

FWIW, we got false positives in other libraries too, including JUnit 5 1.9.0 RC1. The exclusion list is this so far, false positives refer to Python projects using Flask send_file...

That may be true, but CVE-2022-31514 for instance is not.

Well, the GitHub Security Lab is official and no corner shack, and I wouldn't question their expertise or good intentions in the least. But there is obviously something wrong _somewhere_...

> I swear to God if they start issuing CVEs for forks of repositories I'm going to quit. 😆 In particular as that[ Piano LED visualizer](https://github.com/onlaj/Piano-LED-Visualizer) is a Raspberry Pi...

Seems the `runtime` tag is causing it. If you add it to the explicit kiota dependency given above, the error suddenly appears with that one too, and vanishes once you...