Skip to content

Commit a701870

Browse files
committed
fix: add .trivyignore for CVE-2026-34040 and update Go version to 1.25.9
1 parent 4524c76 commit a701870

3 files changed

Lines changed: 11 additions & 3 deletions

File tree

.github/workflows/ci.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -419,6 +419,9 @@ jobs:
419419
exit-code: '1'
420420
ignore-unfixed: true
421421
format: 'table'
422+
# Accepted CVEs (нет доступного исправления в Go module registry):
423+
# CVE-2026-34040 — Moby authz bypass, fix v29.3.1 но в registry только v28.5.2.
424+
trivyignores: .trivyignore
422425

423426
contract:
424427
name: Contract Tests

.trivyignore

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
# Accepted CVEs:
2+
#
3+
# CVE-2026-34040 — Moby authorization bypass. Fix in docker/docker v29.3.1.
4+
# Не доступен в Go module registry (только v28.5.2+incompatible), апстрим
5+
# не публикует v29.x как Go-модуль. Risk mitigated: используем docker client
6+
# только в worker-контейнере, не экспортируем Moby-API наружу.
7+
CVE-2026-34040

go.mod

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,6 @@
11
module github.com/bmstu-itstech/tjudge
22

3-
go 1.25.0
4-
5-
toolchain go1.25.9
3+
go 1.25.9
64

75
require (
86
github.com/DATA-DOG/go-sqlmock v1.5.2

0 commit comments

Comments
 (0)