From 63f94b7eb32c599eaa47fb5da101f8ab4bc358a8 Mon Sep 17 00:00:00 2001 From: sean wibisono Date: Thu, 1 Oct 2026 17:13:47 +1000 Subject: [PATCH 1/2] suppress CVE-2026-102276 in .trivyignore (exp 2027-01-01) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit brace-expansion: Vulnerable code path is not reachable in this configuration — see the linked PR. --- .trivyignore | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.trivyignore b/.trivyignore index 1bf712124..59e6499ca 100644 --- a/.trivyignore +++ b/.trivyignore @@ -99,3 +99,9 @@ CVE-2026-84375 exp:2026-10-10 # svgo runs only at build time optimizing repo-owned static SVGs; no user-upload/sanitization path exists in this static docs site # See: UID2-7852 CVE-2026-84370 exp:2026-10-10 + +# CVE-2026-102276 — brace-expansion (HIGH). Vulnerable code path is not reachable in this +# configuration. +# See the ticket below for the assessment. +# See: [TICKET] +CVE-2026-102276 exp:2027-01-01 From 8358390209f178c718edd3a72f4f6ca0d496b560 Mon Sep 17 00:00:00 2001 From: sean wibisono Date: Thu, 1 Oct 2026 17:13:55 +1000 Subject: [PATCH 2/2] UID2-8003: link suppressions to their tickets --- .trivyignore | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.trivyignore b/.trivyignore index 59e6499ca..e816ccf25 100644 --- a/.trivyignore +++ b/.trivyignore @@ -103,5 +103,5 @@ CVE-2026-84370 exp:2026-10-10 # CVE-2026-102276 — brace-expansion (HIGH). Vulnerable code path is not reachable in this # configuration. # See the ticket below for the assessment. -# See: [TICKET] +# See: UID2-8003 CVE-2026-102276 exp:2027-01-01