From 22afa4db7a5285ab5b04da81308ae06abb82251d Mon Sep 17 00:00:00 2001 From: Will Bradley Date: Wed, 10 Jul 2024 23:16:07 -0600 Subject: [PATCH] updates --- .safety-policy.yml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 .safety-policy.yml diff --git a/.safety-policy.yml b/.safety-policy.yml new file mode 100644 index 0000000..effa8a0 --- /dev/null +++ b/.safety-policy.yml @@ -0,0 +1,42 @@ +--- +version: '3.0' + +scanning-settings: + max-depth: 6 + exclude: [] + include-files: [] + system: + targets: [] + + +report: + dependency-vulnerabilities: + enabled: true + auto-ignore-in-report: + python: + environment-results: true + unpinned-requirements: true + cvss-severity: [] + vulnerabilities: + 70612: + reason: CVE-2019-8341 is disputed and no fix is apparent. + expires: 2025-07-10 + + +fail-scan-with-exit-code: + dependency-vulnerabilities: + enabled: true + fail-on-any-of: + cvss-severity: + - critical + - high + - medium + exploitability: + - critical + - high + - medium + +security-updates: + dependency-vulnerabilities: + auto-security-updates-limit: + - patch