Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Trivy currently finds the GMS-2021-101 vulnerability in every pipeline run. This vulnerability is introduced through a package used by cosign that in turn however pins to a version of the package in which the vulnerability is fixed. Thus this is a false-positive and is therefore allowlisted.
- Loading branch information