Skip to content

Add low-severity CVEs to .trivyignore#5

Merged
dash14 merged 1 commit intomainfrom
security/add-trivyignore-for-non-impacting-cves
Mar 3, 2026
Merged

Add low-severity CVEs to .trivyignore#5
dash14 merged 1 commit intomainfrom
security/add-trivyignore-for-non-impacting-cves

Conversation

@dash14
Copy link
Copy Markdown
Owner

@dash14 dash14 commented Mar 3, 2026

Summary

  • Add 2 low-severity CVEs with no practical impact to .trivyignore
    • CVE-2026-1229: CIRCL ecc/p384 CombinedMult incorrect value — buildkitd does not use CombinedMult directly; ECDH/ECDSA are unaffected
    • CVE-2026-24515: libexpat XML_ExternalEntityParserCreate encoding handler issue — no external XML entity processing path exists in this product

Suppress 2 additional CVEs with no practical impact:
- CVE-2026-1229: CIRCL CombinedMult not used by buildkitd
- CVE-2026-24515: No external XML entity processing in this product
@dash14 dash14 merged commit 2d65c33 into main Mar 3, 2026
5 checks passed
@dash14 dash14 deleted the security/add-trivyignore-for-non-impacting-cves branch March 3, 2026 14:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant