NOTICK: Remaining snyk waivers updated for Corda OS 4.10

This commit is contained in:
Ritu 2023-01-04 12:10:48 +00:00
parent a98f17922c
commit e2ee13196d

6
.snyk
View File

@ -206,7 +206,7 @@ ignore:
not yaml. So given this Corda is not susceptible to this
vulnerability.Cordapp authors should exercise their own judgment if
using this library directly in their cordapp.
expires: 2023-02-03T11:35:04.385Z
expires: 2023-03-03T11:35:04.385Z
created: 2023-01-04T11:35:04.414Z
SNYK-JAVA-IONETTY-3167773:
- '*':
@ -216,13 +216,13 @@ ignore:
but it is not used in Corda, which uses a custom binary protocol
secured by mutually authenticated TLS. The vulnerability relating to
HTTP Response splitting is not exposed.
expires: 2023-02-03T11:40:51.456Z
expires: 2023-03-03T11:40:51.456Z
created: 2023-01-04T11:40:51.467Z
SNYK-JAVA-COMH2DATABASE-3146851:
- '*':
reason: >-
Corda does not make use of the H2 web admin console, so it not
susceptible to this reported vulnerability
expires: 2023-02-03T11:45:11.295Z
expires: 2023-03-03T11:45:11.295Z
created: 2023-01-04T11:45:11.322Z
patch: {}