djfdyuruiry/improved-yarn-audit

Temporarily supress advisory

Opened this issue · 0 comments

Hi, I really like this tool for its ability to suppress advisories that can't be reasonably addressed at the moment. Given the issues usually get resolved sometime later, it would be great to have the ability to specify the expiration of ignoring advisories in the .iarc file (so we don't have to manually revisit them), perhaps by optionally passing the expiration ISO8601 timestamp next to the suppressed advisory, what do you think? There's perhaps some more sensible approach I didn't think of