From cf8abb79892882d8c8af04cf53e5a212f69bc230 Mon Sep 17 00:00:00 2001 From: martincostello Date: Fri, 14 Feb 2025 13:27:36 +0000 Subject: [PATCH] Add change note Add change note. --- .../ql/src/change-notes/2025-02-14-docker-false-positives.md | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 actions/ql/src/change-notes/2025-02-14-docker-false-positives.md diff --git a/actions/ql/src/change-notes/2025-02-14-docker-false-positives.md b/actions/ql/src/change-notes/2025-02-14-docker-false-positives.md new file mode 100644 index 000000000000..9dadea510f76 --- /dev/null +++ b/actions/ql/src/change-notes/2025-02-14-docker-false-positives.md @@ -0,0 +1,5 @@ +--- +category: minorAnalysis +--- + +* Fix CWE-829 false positives for Docker GitHub actions pinned by the container's SHA256 digest.