From 65fb146e7618fffddcd3a3a50de0dc895e9f0399 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pedro=20Mart=C3=ADn?= Date: Tue, 29 Sep 2026 17:04:46 +0200 Subject: [PATCH] chore(trivy): suppress fast-uri CVE-2026-84292 (#12907) --- .trivyignore.yaml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/.trivyignore.yaml b/.trivyignore.yaml index f572065625..27e6ccf24b 100644 --- a/.trivyignore.yaml +++ b/.trivyignore.yaml @@ -68,7 +68,7 @@ vulnerabilities: expired_at: 2026-11-30 # Declared in the SPDX manifest that ships inside PowerShell's MicrosoftTeams module - # (Modules/MicrosoftTeams/7.9.0/_manifest/spdx_2.2/manifest.spdx.json). Trivy reads that + # (Modules/MicrosoftTeams/8.0.0/_manifest/spdx_2.2/manifest.spdx.json). Trivy reads that # SBOM and reports what it declares, which is not the same as what the image contains: # there is no Node runtime and no node_modules anywhere in the image, and the .NET # assemblies target net472, a Windows-only framework. Nothing here is reachable, and none @@ -129,6 +129,10 @@ vulnerabilities: purls: - "pkg:npm/fast-uri" expired_at: 2027-01-31 + - id: CVE-2026-84292 + purls: + - "pkg:npm/fast-uri" + expired_at: 2027-01-31 - id: CVE-2026-69192 purls: - "pkg:npm/ip-address"