motioneye-project / motioneye

A web frontend for the motion daemon.
GNU General Public License v3.0
3.99k stars 655 forks source link

ci: ignore another newly failing Python safety CVE #3000

Closed MichaIng closed 5 months ago

MichaIng commented 5 months ago

The very same applies as for CVE-2018-20225: disputed, ignored since years, and whichever database update triggered safety to suddenly fail on it, while there is no solution, and never will be one: https://github.com/pyupio/safety/issues/527

Not sure who to blame here, whether the NIST NVD database update triggered them to be recognised by safety now (with 30 days delay as free user), or whether "the information ... curated by our (Safety's) Cybersecurity Intelligence Team" was not done well.

I hope it stops failing on more ancient disputed CVEs, otherwise I suggest to drop safety and move to another tool which better handles disputed CVEs.