Commit 9ae49c7
fix(ci): add .trivyignore for unfixable transitive CVEs (docker, brace-expansion)
CVE-2026-34040, CVE-2026-33997: github.com/docker/docker v28.5.2 (no upstream fix)
CVE-2026-33750: brace-expansion npm dep in website (no fix available)
All are transitive dependencies with no actionable fix. Docker CVEs only
affect integration test infra, not production code.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 0c85370 commit 9ae49c7
1 file changed
Lines changed: 12 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
0 commit comments