Skip to content

UID2-7962: suppress CVE-2026-93990 in .trivyignore - #675

Merged
swibi-ttd merged 2 commits into
mainfrom
swi-suppress-20260925-131724
Sep 25, 2026
Merged

swibi-ttd merged 2 commits into
mainfrom
swi-suppress-20260925-131724

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Suppresses CVE-2026-93990 (HIGH, libexpat (Alpine base-image native C library)) — present in the image but not reachable from this service. Expiry 2026-12-25 (3 months). No code fix.

Reachability alone determines suppress-vs-fix — a fixed version existing upstream does not make an unreachable path exploitable. Change the expiry in review if you want a different window.

The reachability analysis behind this is recorded on the ticket named in the PR title.


Opened by uid2-vul-scan-agent (general_use_claude-opus-4-8), verdict confidence high. Please sanity-check the reachability argument on the ticket before approving.

unknown package is present but not reachable from this service — see the linked PR. Reachability alone determines suppress-vs-fix.
@swibi-ttd swibi-ttd changed the title [TICKET] suppress CVE-2026-93990 in .trivyignore UID2-7962: suppress CVE-2026-93990 in .trivyignore Sep 25, 2026
@swibi-ttd
swibi-ttd merged commit 1dafd3a into main Sep 25, 2026
4 of 6 checks passed
@swibi-ttd
swibi-ttd deleted the swi-suppress-20260925-131724 branch September 25, 2026 05:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants