From 39a2a79524bd60a89c14a47ab25e0021f3ab59af Mon Sep 17 00:00:00 2001 From: maziggy Date: Wed, 20 May 2026 12:42:37 +0200 Subject: [PATCH] This reverts commit 929aae7202f20b592ce96a7bac18d229bc432aca. --- scripts/pip-audit.sh | 15 --------------- 1 file changed, 15 deletions(-) delete mode 100755 scripts/pip-audit.sh diff --git a/scripts/pip-audit.sh b/scripts/pip-audit.sh deleted file mode 100755 index 207b5d37d..000000000 --- a/scripts/pip-audit.sh +++ /dev/null @@ -1,15 +0,0 @@ -#!/usr/bin/env bash -# Local pip-audit wrapper — mirrors the ignore list in -# .github/workflows/security.yml so `./scripts/pip-audit.sh` matches what CI sees. -# Keep both sides in sync when adding or removing ignores. -# -# CVE-2025-45768 (PYSEC-2025-183 / GHSA-65pc-fj4g-8rjx): disputed by PyJWT -# maintainers; no fix version exists. Bambuddy uses secrets.token_urlsafe(64) -# (~86 chars) and rejects file-loaded secrets shorter than 32 chars -# (backend/app/core/auth.py:177, :184). Safe to ignore permanently. -set -euo pipefail -source /opt/claude/projects/bambuddy/venv/bin/activate - -exec pip-audit \ - --ignore-vuln CVE-2025-45768 \ - "$@"