Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fix vulnerable dependencies in web API package (#153)
* Update to owasp dep check 0.0.19, fixes dependency vulnerabilities * Remove omit=dev from npm audit compliance check, now owasp dep check dependencies are fixed * Latest package lock file for web api * Add false positive for CVE-2022-25878 in protobufjs 6.11.3 OSSIndex/vulns#305 * Allow WTFPL in allowed licenses for the web API (used by dependency of OWASP dep check, considered a permissive license) * False positives for vulnerabilities in AWS hotpatch for Log4j (we are not using AWS hotpatch) * False positives for vulnerabilities in AWS hotpatch for Log4j (we are not using AWS hotpatch)
- Loading branch information