NOTICK: Remaining snyk waivers updated for Corda OS 4.10

This commit is contained in:
Ritu 2023-01-04 12:10:48 +00:00
parent a98f17922c
commit e2ee13196d

6
.snyk
View File

@ -206,7 +206,7 @@ ignore:
not yaml. So given this Corda is not susceptible to this not yaml. So given this Corda is not susceptible to this
vulnerability.Cordapp authors should exercise their own judgment if vulnerability.Cordapp authors should exercise their own judgment if
using this library directly in their cordapp. using this library directly in their cordapp.
expires: 2023-02-03T11:35:04.385Z expires: 2023-03-03T11:35:04.385Z
created: 2023-01-04T11:35:04.414Z created: 2023-01-04T11:35:04.414Z
SNYK-JAVA-IONETTY-3167773: SNYK-JAVA-IONETTY-3167773:
- '*': - '*':
@ -216,13 +216,13 @@ ignore:
but it is not used in Corda, which uses a custom binary protocol but it is not used in Corda, which uses a custom binary protocol
secured by mutually authenticated TLS. The vulnerability relating to secured by mutually authenticated TLS. The vulnerability relating to
HTTP Response splitting is not exposed. HTTP Response splitting is not exposed.
expires: 2023-02-03T11:40:51.456Z expires: 2023-03-03T11:40:51.456Z
created: 2023-01-04T11:40:51.467Z created: 2023-01-04T11:40:51.467Z
SNYK-JAVA-COMH2DATABASE-3146851: SNYK-JAVA-COMH2DATABASE-3146851:
- '*': - '*':
reason: >- reason: >-
Corda does not make use of the H2 web admin console, so it not Corda does not make use of the H2 web admin console, so it not
susceptible to this reported vulnerability susceptible to this reported vulnerability
expires: 2023-02-03T11:45:11.295Z expires: 2023-03-03T11:45:11.295Z
created: 2023-01-04T11:45:11.322Z created: 2023-01-04T11:45:11.322Z
patch: {} patch: {}