Skip to content

ci: ignore unfixed CVEs in scheduled scan to stop weekly noise issues - #42

Merged
gifi71 merged 1 commit into
mainfrom
ci/scheduled-scan-ignore-unfixed
Jun 21, 2026
Merged

ci: ignore unfixed CVEs in scheduled scan to stop weekly noise issues#42
gifi71 merged 1 commit into
mainfrom
ci/scheduled-scan-ignore-unfixed

Conversation

@gifi71

@gifi71 gifi71 commented Jun 21, 2026

Copy link
Copy Markdown
Owner

The weekly scheduled-scan.yml files a Critical vulnerabilities found in latest image issue every Monday for Debian-12 CVEs that have no upstream fix (e.g. perl-base CVE-2026-42496 / CVE-2026-8376). Issues #28#35 are all instances of this.

Adds ignore-unfixed: true to the critical-check step so it matches the CI gate added in #41. Only fixable-but-unpatched CRITICALs now open an issue.

The SARIF upload step is left untouched, so the Security tab keeps full visibility.

The weekly scheduled-scan filed a 'Critical vulnerabilities found' issue every
Monday for Debian-12 CVEs that have no upstream fix (e.g. perl-base
CVE-2026-42496/-8376). Add 'ignore-unfixed: true' to the critical-check step so
it matches the CI gate (.github/workflows/ci.yml); only fixable-but-unpatched
CRITICALs now open an issue.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant