From ac2a3896aa30c7358a3df567d0078c429ce006c4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Michael=20P=C3=B6hn?= Date: Thu, 30 Nov 2023 17:49:55 +0100 Subject: [PATCH] =?UTF-8?q?=F0=9F=A9=B9=20fix=20bandit=20warning?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit F-Droid server doesn't fetch pip dependencies directly from mercurial/hg repositories. So https://data.safetycli.com/v/62044/f17/ is not affecting us. Hence we can ingore it. --- .safety-policy.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.safety-policy.yml b/.safety-policy.yml index afc0b83e..7d9ec149 100644 --- a/.safety-policy.yml +++ b/.safety-policy.yml @@ -14,3 +14,6 @@ security: 60841: reason: GitPython comes from Debian https://security-tracker.debian.org/tracker/CVE-2023-41040 expires: '2025-01-31' + 62044: + reason: "F-Droid doesn't fetch pip dependencies directly from hg/mercurial repositories: https://data.safetycli.com/v/62044/f17/" + expires: '2025-01-31'