minder
minder copied to clipboard
The OSV evaluator should allow ignoring CVEs
Some packages have CVEs that will never be fixed. This might mean that updates bumping that package as a dep would perpetually be marked as changes requested by minder.
We should extend the OSV evaluator to allow for ignoring CVEs.
Will revisit once we refactor our OSV rule.