Christian Bollmeyer
Christian Bollmeyer
FWIW, we got false positives in other libraries too, including JUnit 5 1.9.0 RC1. The exclusion list is this so far, false positives refer to Python projects using Flask send_file...
That may be true, but CVE-2022-31514 for instance is not.
Well, the GitHub Security Lab is official and no corner shack, and I wouldn't question their expertise or good intentions in the least. But there is obviously something wrong _somewhere_...
> I swear to God if they start issuing CVEs for forks of repositories I'm going to quit. 😆 In particular as that[ Piano LED visualizer](https://github.com/onlaj/Piano-LED-Visualizer) is a Raspberry Pi...
Seems the `runtime` tag is causing it. If you add it to the explicit kiota dependency given above, the error suddenly appears with that one too, and vanishes once you...