diff --git a/.github/workflows/checks.yml b/.github/workflows/checks.yml index 95d343cb6..9022d79a0 100644 --- a/.github/workflows/checks.yml +++ b/.github/workflows/checks.yml @@ -76,7 +76,7 @@ jobs: - uses: pypa/gh-action-pip-audit@v1.0.4 with: inputs: requirements.txt - ignore-vulns: PYSEC-2022-237 + ignore-vulns: GHSA-8fww-64cx-x8p5 static-scan: runs-on: ubuntu-latest diff --git a/.github/workflows/daily_checks.yml b/.github/workflows/daily_checks.yml index dfd0e83b4..04be11aea 100644 --- a/.github/workflows/daily_checks.yml +++ b/.github/workflows/daily_checks.yml @@ -30,7 +30,7 @@ jobs: - uses: pypa/gh-action-pip-audit@v1.0.4 with: inputs: requirements.txt - ignore-vulns: PYSEC-2022-237 + ignore-vulns: GHSA-8fww-64cx-x8p5 static-scan: runs-on: ubuntu-latest diff --git a/Makefile b/Makefile index e09fba6e9..d65bbad0d 100644 --- a/Makefile +++ b/Makefile @@ -67,7 +67,7 @@ freeze-requirements: ## Pin all requirements including sub dependencies into req audit: pipenv requirements > requirements.txt pipenv requirements --dev > requirements_for_test.txt - pipenv run pip-audit -r requirements.txt --ignore-vuln PYSEC-2022-237 + pipenv run pip-audit -r requirements.txt --ignore-vuln GHSA-8fww-64cx-x8p5 -pipenv run pip-audit -r requirements_for_test.txt .PHONY: static-scan