@@ -38,6 +38,15 @@ ignore:
3838 - vulnerability : CVE-2026-6100
3939 - vulnerability : CVE-2026-4786
4040 - vulnerability : GHSA-pc3f-x583-g7j2
41+ - vulnerability : CVE-2026-3298
42+ - vulnerability : GHSA-q339-8rmv-2mhv
43+ package :
44+ name : erb
45+ version : 4.0.3
46+ - vulnerability : GHSA-mh2q-q3fh-2475
47+ package :
48+ name : go.opentelemetry.io/otel
49+ version : v1.40.0
4150# node_24 vulnerabilities
4251 - vulnerability : GHSA-c2c7-rcm5-vvqj
4352 - vulnerability : GHSA-7r86-cg39-jmmj
@@ -53,8 +62,24 @@ ignore:
5362 - vulnerability : GHSA-2599-h6xx-hpxp
5463# eps-storage-terraform vulnerabilities
5564 - vulnerability : CVE-2025-68119
65+ - vulnerability : GHSA-mh2q-q3fh-2475
66+ package :
67+ name : go.opentelemetry.io/otel
68+ version : v1.38.0
69+ - vulnerability : GHSA-mh2q-q3fh-2475
70+ package :
71+ name : go.opentelemetry.io/otel
72+ version : v1.39.0
5673# eps-data-extract vulnerabilities
5774 - vulnerability : GHSA-6fmv-xxpf-w3cw
75+ - vulnerability : CVE-2026-34282
76+ package :
77+ name : openjdk
78+ version : 17.0.18+8
79+ - vulnerability : CVE-2026-22016
80+ package :
81+ name : openjdk
82+ version : 17.0.18+8
5883# fhir-facade vulnerabilities
5984 - vulnerability : CVE-2022-26485
6085 - vulnerability : CVE-2022-26486
@@ -70,10 +95,33 @@ ignore:
7095 - vulnerability : CVE-2025-53066
7196 - vulnerability : CVE-2026-21945
7297 - vulnerability : CVE-2026-21932
98+ package :
99+ name : openjdk
100+ version : 20.0.2+9-78
101+ - vulnerability : CVE-2026-22016
102+ package :
103+ name : openjdk
104+ version : 20.0.2+9-78
105+ - vulnerability : CVE-2026-34282
106+ package :
107+ name : jdk
108+ version : 20.0.2+9-78
109+ - vulnerability : CVE-2026-22016
110+ package :
111+ name : jdk
112+ version : 20.0.2+9-78
73113# node-24_python_3_14_java_24 vulnerabilities
74114 - vulnerability : GHSA-6fmv-xxpf-w3cw
75115 - vulnerability : CVE-2025-53066
76116 - vulnerability : CVE-2026-21945
77117 - vulnerability : CVE-2026-21932
78118 - vulnerability : CVE-2026-27143
79119 - vulnerability : CVE-2026-27144
120+ - vulnerability : CVE-2026-34282
121+ package :
122+ name : openjdk
123+ version : 24.0.2+12
124+ - vulnerability : CVE-2026-22016
125+ package :
126+ name : openjdk
127+ version : 24.0.2+12
0 commit comments