From 3ddc5b183a0249948ed4ee7cb10fbab3a376592b Mon Sep 17 00:00:00 2001 From: sean wibisono Date: Wed, 30 Sep 2026 15:00:01 +1000 Subject: [PATCH] suppress 2 CVEs in .trivyignore (exp 2026-12-30) - CVE-2026-76844 - CVE-2026-84292 CVE-2026-76844: Required attack preconditions are absent in this configuration. CVE-2026-84292: Vulnerable code path is not reachable in this configuration. See the linked tickets for the per-CVE impact assessments. --- .trivyignore | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/.trivyignore b/.trivyignore index 1bf712124..b8ab4b9e1 100644 --- a/.trivyignore +++ b/.trivyignore @@ -99,3 +99,15 @@ CVE-2026-84375 exp:2026-10-10 # svgo runs only at build time optimizing repo-owned static SVGs; no user-upload/sanitization path exists in this static docs site # See: UID2-7852 CVE-2026-84370 exp:2026-10-10 + +# CVE-2026-76844 — webpack-dev-middleware (HIGH). Required attack preconditions are absent in +# this configuration. +# See the ticket below for the assessment. +# See: [TICKET] +CVE-2026-76844 exp:2026-12-30 + +# CVE-2026-84292 — fast-uri (HIGH). Vulnerable code path is not reachable in this +# configuration. +# See the ticket below for the assessment. +# See: [TICKET] +CVE-2026-84292 exp:2026-12-30