ort icon indicating copy to clipboard operation
ort copied to clipboard

Vulnerablities not getting overidden : set-value:0.2.0

Open kvy1kor opened this issue 2 years ago • 5 comments

Hello Team,

i have written the resolutions for vulnerablities and rule_violations inside my .ort.yml file as mentioned below.

But the overide information is not working for vulnerbalities and but it's only taking rule_violations as input.

.ort.yml file

resolutions:
  vulnerabilities:
  - id: "GHSA-4jqc-8m5r-9rpr"
    reason: "INEFFECTIVE_VULNERABILITY"
    comment: "GHSA-4jqc-8m5r-9rpr is a false positive"
  rule_violations:
  - message: ".*NPM::konyvtar-js:1.5.1.*"
    reason: "CANT_FIX_EXCEPTION"
    comment: "A comment further explaining why the reason above is applicable."  

Component Used : set-value:0.2.0

image

image

Could someone look into it and provide the feedback.

Thank You,

kvy1kor avatar Jul 18 '23 13:07 kvy1kor

Hello Team,

Could someone look into it and provide the feedback.

Thank You, Kavya B S

kvy1kor avatar Jul 20 '23 04:07 kvy1kor

Hi @kvy1kor,

please understand that, despite this project being used in production by many commercial adopters, the maintainer team is a group of volunteers. As such we cannot always respond to issues within a few days only due to other day-job duties.

If you need commercial-grade support for ORT, there are a few companies that offer this by now. Feel free to reach out to me privately in case you're interested.

sschuberth avatar Jul 20 '23 06:07 sschuberth

Hello @sschuberth, Thank you very much for your response.

kvy1kor avatar Jul 20 '23 08:07 kvy1kor

@tsteenbe offered to try reproducing the issue.

sschuberth avatar Nov 19 '24 09:11 sschuberth

@tsteenbe offered to try reproducing the issue.

Do we have any update here @tsteenbe? Is the issue still reproducible with the latest ORT release @kvy1kor?

sschuberth avatar Apr 16 '25 14:04 sschuberth

Is this issue reproducible by anyone using ORT 66.0.1?

sschuberth avatar Aug 06 '25 14:08 sschuberth