FAQ
My Vulnerability Doesn't Have a Fix Available
1 min
on occasion there may be vulnerabilities located that do not have a newer vulnerability free version available to upgrade too research the vulnerability use the soos vulnerability research docid\ laojje8flnuj0k4onkru0 pages to determine the best course of action use the information provided in the vulnerability description and references sections to determine an appropriate course of action to make your own correction in your project this may involve self selecting a different package as a replacement, or making customizations to the selected package to remedy any identified vulnerabilities attest, suppress, snooze, or waive the vulnerability depending on the urgency of the vulnerability and/or the development stage of your project, you may decide to suppress the issue temporarily or even permanently in some cases you may choose to suppress with an attestation if the issue is a false positive, or your code is deemed not vulnerable use the creating issue suppressions & attestations docid\ inbrolrzqnfvkihn08fnd page to determine the appropriate type of suppression