Skip to content

[TICKET] suppress 2 CVEs in .trivyignore - #1069

Open
swibi-ttd wants to merge 1 commit into
mainfrom
swi-suppress-20260930-143207
Open

swibi-ttd wants to merge 1 commit into
mainfrom
swi-suppress-20260930-143207

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Suppresses 2 vulnerabilities in .trivyignore, expiry 2026-12-30 (3 months). No code fixes.

If another suppression PR is open on this repo, this one supersedes it. Each scan run raises a fresh branch carrying every outstanding suppression, so the newest PR is a superset of the older ones — merge this and close the rest rather than merging both, which would conflict on the same append.

The assessment for each finding is recorded on its ticket.

  • CVE-2026-76844 — HIGH, webpack-dev-middleware: Required attack preconditions are absent in this configuration.
  • CVE-2026-84292 — HIGH, fast-uri: Vulnerable code path is not reachable in this configuration.

Opened by uid2-vul-scan-agent (general_use_claude-opus-4-8) for the automated finding(s) above. Verdict confidence: medium. Please sanity-check each assessment on its ticket before approving.

- CVE-2026-76844
- CVE-2026-84292

CVE-2026-76844: Required attack preconditions are absent in this configuration.
CVE-2026-84292: Vulnerable code path is not reachable in this configuration.
See the linked tickets for the per-CVE impact assessments.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant