fix(release): suppress wish GHSA alias in grype, fold rc tags into launch notes
The existing .grype.yaml ignore listed the wish SCP traversal only by CVE id; grype's db now matches it as GHSA-xjvp-7243-rg9h and ignores are exact-id, so the rc.2 scan gate tripped on an already-triaged finding. List both ids. Vulnerable SCP middleware is never compiled in; real fix is the charm v2 stack migration (#126). cliff.toml ignore_tags folds rc tags into the next real release so v0.1.0's notes cover full history instead of commits-since-rc.2.
This commit was merged in pull request #127.
This commit is contained in:
@@ -24,6 +24,10 @@ split_commits = false
|
||||
protect_breaking_commits = false
|
||||
filter_commits = false
|
||||
tag_pattern = "v[0-9].*"
|
||||
# rc tags are pipeline rehearsals, not releases — without this, the final
|
||||
# tag's notes would only cover commits since the last rc (near-empty for
|
||||
# v0.1.0). Ignored tags fold their commits into the next real release.
|
||||
ignore_tags = "v.*-rc.*"
|
||||
topo_order = false
|
||||
sort_commits = "oldest"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user