From bddb380b1eaa8572e78ab1844f2727b013f5bed2 Mon Sep 17 00:00:00 2001 From: Daniel Watkins Date: Wed, 5 Feb 2025 16:14:38 -0500 Subject: [PATCH] argo-cd-2.14: add false-positive-determination event for GHSA-274v-mgcv-cm8j --- argo-cd-2.14.advisories.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/argo-cd-2.14.advisories.yaml b/argo-cd-2.14.advisories.yaml index 6f7f501b0d..09c419e9b3 100644 --- a/argo-cd-2.14.advisories.yaml +++ b/argo-cd-2.14.advisories.yaml @@ -20,3 +20,11 @@ advisories: componentType: go-module componentLocation: /usr/local/bin/argocd scanner: grype + - timestamp: 2025-02-06T14:04:05Z + type: false-positive-determination + data: + type: component-vulnerability-mismatch + note: |- + The fixed version of GitOps Engine was integrated before 2.14 + released in + https://github.com/argoproj/argo-cd/commit/d59c85c5eb55d5ccba3ef5ce6624306a1113ce00