Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .trivyignore
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,13 @@ CVE-2026-1584 exp:2026-08-27
# jackson-core async parser DoS - not exploitable, services only use synchronous ObjectMapper API
# See: UID2-6670
GHSA-72hv-8253-57qq exp:2026-09-01

# libexpat NULL pointer dereference in Alpine base image - not exploitable, our Java services do not use libexpat
# Fixed in libexpat 2.7.5, not yet available in eclipse-temurin Alpine 3.23 base image
# See: UID2-6806
CVE-2026-32776 exp:2026-04-25

# Trivy reports CVE-2026-32776 with transposed digits (32767 instead of 32776) - this is a known Trivy bug
# See: https://github.com/aquasecurity/trivy/discussions/10412 and UID2-6806
# This entry can be removed once Trivy fixes the typo
CVE-2026-32767 exp:2026-04-25
Loading