GSA / notifications-admin

The UI of Notify.gov
https://notify.gov
Other
11 stars 2 forks source link

Add redis ID to ignore vulnerability list in audit/no current fix #2144

Open A-Shumway42 opened 16 hours ago

A-Shumway42 commented 16 hours ago

A note to PR reviewers: it may be helpful to review our code review documentation to know what to keep in mind while reviewing pull requests.

Description

Adding Python dependency ID to Github actions ignore vulnerabilities list for now so our builds can pass.

Security Considerations

Vulnerability: Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.