This repository is used to manage shared allowlists for security issues (e.g., CVEs) identified by automated scanners.
Adding an entry to these allowlists typically means that we've determined the issue doesn't apply to how we use the impacted component. We may still update the component as part of routine dependency updates at a later date.