Skip to content

UID2-7904, UID2-7908, UID2-7900, UID2-7901, UID2-7907, UID2-7902, UID2-7905, UID2-7903, UID2-7906, UID2-7909: suppress 10 CVEs in .trivyignore - #218

Open
swibi-ttd wants to merge 2 commits into
mainfrom
swi-suppress-20260918-113501
Open

swibi-ttd wants to merge 2 commits into
mainfrom
swi-suppress-20260918-113501

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Suppresses 10 vulnerabilities in .trivyignore, expiry 2026-12-18 (3 months). No code fixes — each is present in the image but not reachable from this service.

Reachability alone determines suppress-vs-fix: a fixed version existing upstream does not make an unreachable path exploitable. Change any expiry in review if you want a different window.

If another suppression PR is open on this repo, this one supersedes it. Each scan run raises a fresh branch carrying every outstanding suppression, so the newest PR is a superset of the older ones — merge this and close the rest rather than merging both, which would conflict on the same append.

The reachability analysis behind each is recorded on the ticket named in the PR title.

  • CVE-2024-21538 — HIGH, cross-spawn 7.0.3 (bundled inside npm at usr/local/lib/node_modules/npm/node_modules/cross-spawn in the node:20.11.0-alpine3.18 base image)
  • CVE-2024-29415 — HIGH, ip (node-ip) 2.0.0 (through 2.0.1); bundled inside the npm CLI in the node:20.11.0-alpine3.18 base image
  • CVE-2024-6119 — HIGH, libcrypto3 (Alpine base-image OpenSSL) 3.1.4-r5 (shipped in node:20.11.0-alpine3.18 base image)
  • CVE-2025-26519 — HIGH, musl (Alpine base image libc) 1.2.4-r2 (musl 0.9.13 through 1.2.5, in node:20.11.0-alpine3.18)
  • CVE-2025-64756 — HIGH, glob 10.3.10 (bundled inside npm in the node:20.11.0-alpine3.18 base image)
  • CVE-2026-13149 — HIGH, brace-expansion (bundled inside the npm CLI in the node:20.11.0-alpine3.18 base image) 2.0.1 (npm's bundled copy in node:20.11.0-alpine3.18)
  • CVE-2026-13676 — HIGH, fast-uri 3.1.2 (installed; vulnerable range 2.3.1–4.0.0)
  • CVE-2026-14257 — HIGH, brace-expansion (npm — npm CLI's own bundled copy in the node base image) 2.0.1 (bundled at usr/local/lib/node_modules/npm/node_modules/brace-expansion inside node:20.11.0-alpine3.18)
  • CVE-2026-16221 — HIGH, fast-uri 3.1.2 (installed); affected range 2.3.1–4.1.0 incl. 3.x up to 3.1.3
  • CVE-2026-26996 — HIGH, minimatch 9.0.3 (bundled inside the npm CLI in the node:20.11.0-alpine3.18 base image)

Opened by uid2-vul-scan-agent (general_use_claude-opus-4-8) for the automated finding(s) above. Verdict confidence: high. Please sanity-check each reachability argument on its ticket before approving.

- CVE-2024-21538
- CVE-2024-29415
- CVE-2024-6119
- CVE-2025-26519
- CVE-2025-64756
- CVE-2026-13149
- CVE-2026-13676
- CVE-2026-14257
- CVE-2026-16221
- CVE-2026-26996

Each is present but not reachable from this service; see the linked tickets for the per-CVE impact assessments. Reachability alone determines suppress-vs-fix.
…2-7905, UID2-7903, UID2-7906, UID2-7909: link suppressions to their tickets
@swibi-ttd swibi-ttd changed the title [TICKET] suppress 10 CVEs in .trivyignore UID2-7904, UID2-7908, UID2-7900, UID2-7901, UID2-7907, UID2-7902, UID2-7905, UID2-7903, UID2-7906, UID2-7909: suppress 10 CVEs in .trivyignore Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant