Skip to content

UID2-8003: suppress CVE-2026-102276 in .trivyignore - #1072

Merged
swibi-ttd merged 2 commits into
mainfrom
swi-suppress-20261001-164540
Oct 2, 2026
Merged

swibi-ttd merged 2 commits into
mainfrom
swi-suppress-20261001-164540

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Suppresses CVE-2026-102276 (HIGH, brace-expansion) — Vulnerable code path is not reachable in this configuration. Expiry 2027-01-01 (3 months). No code fix.

The assessment is recorded on the ticket named in the PR title.


Opened by uid2-vul-scan-agent (general_use_claude-opus-4-8), verdict confidence medium. Please sanity-check the assessment on the ticket before approving.

brace-expansion: Vulnerable code path is not reachable in this configuration — see the linked PR.
@swibi-ttd swibi-ttd changed the title [TICKET] suppress CVE-2026-102276 in .trivyignore UID2-8003: suppress CVE-2026-102276 in .trivyignore Oct 1, 2026
@swibi-ttd
swibi-ttd merged commit edc6c21 into main Oct 2, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants