Skip to content

Conversation

egibs
Copy link
Member

@egibs egibs commented Jun 6, 2025

This PR cleans up a few remaining false positives.

The rule triggering against LTP's Dirtypipe test is valid since it's testing the actual vector of attack, but it makes sense to treat it like other red-teaming tools. The other finding was an outright false-positive.

@egibs egibs requested a review from antitree June 6, 2025 13:26
@egibs egibs merged commit 47f8fe7 into chainguard-dev:main Jun 6, 2025
12 checks passed
@egibs egibs deleted the 20250606-fpr branch June 25, 2025 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants