Commit dedee4e
Add .trivyignore for npm-bundled CVEs pending upstream fix
CVE-2026-27903, CVE-2026-27904 (minimatch) and CVE-2026-29786 (tar) are
present in packages bundled inside npm itself, not in our application
dependencies. They cannot be resolved by updating package.json — a fix
requires a new npm release.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 77d0d2f commit dedee4e
1 file changed
Lines changed: 13 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
0 commit comments