You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# osv-scanner suppressions for advisories without an available fix.
#
# Mirrors the inline --ignore-vuln list passed to pip-audit in
# .github/workflows/pr-checks.yml so both scanners stay in sync. pip-audit
# accepts ignores as CLI flags; osv-scanner only reads them from this TOML.
# When an advisory is fixed upstream, drop the entry here AND remove the
# matching pip-audit flag in the same PR.
[[IgnoredVulns]]
id = "CVE-2026-49265"
reason = "oauthlib 3.3.1 PKCE timing side channel in the server-side code_challenge check, which coder-eval never runs (oauthlib is transitive via azure-monitor-opentelemetry-exporter -> msrest -> requests-oauthlib). The fix, 4.0.0, is a major bump still inside the safe-chain minimum package age; revisit next month."
[[IgnoredVulns]]
id = "GHSA-hj66-6f7g-4r5v"
reason = "CVE-2026-49264: oauthlib 3.3.1 RevocationEndpoint JSONP callback injection (only with enable_jsonp=True), a server-side OAuth endpoint coder-eval never runs (oauthlib is transitive via azure-monitor-opentelemetry-exporter -> msrest -> requests-oauthlib). The fix, 4.0.0, is a major bump still inside the safe-chain minimum package age; revisit next month."