chore(trivy): suppress fast-uri CVE-2026-84292 (#12907)

This commit is contained in:
Pedro Martín
2026-09-29 17:04:46 +02:00
committed by GitHub
parent 5ea363d582
commit 65fb146e76
+5 -1
View File
@@ -68,7 +68,7 @@ vulnerabilities:
expired_at: 2026-11-30 expired_at: 2026-11-30
# Declared in the SPDX manifest that ships inside PowerShell's MicrosoftTeams module # Declared in the SPDX manifest that ships inside PowerShell's MicrosoftTeams module
# (Modules/MicrosoftTeams/7.9.0/_manifest/spdx_2.2/manifest.spdx.json). Trivy reads that # (Modules/MicrosoftTeams/8.0.0/_manifest/spdx_2.2/manifest.spdx.json). Trivy reads that
# SBOM and reports what it declares, which is not the same as what the image contains: # SBOM and reports what it declares, which is not the same as what the image contains:
# there is no Node runtime and no node_modules anywhere in the image, and the .NET # there is no Node runtime and no node_modules anywhere in the image, and the .NET
# assemblies target net472, a Windows-only framework. Nothing here is reachable, and none # assemblies target net472, a Windows-only framework. Nothing here is reachable, and none
@@ -129,6 +129,10 @@ vulnerabilities:
purls: purls:
- "pkg:npm/fast-uri" - "pkg:npm/fast-uri"
expired_at: 2027-01-31 expired_at: 2027-01-31
- id: CVE-2026-84292
purls:
- "pkg:npm/fast-uri"
expired_at: 2027-01-31
- id: CVE-2026-69192 - id: CVE-2026-69192
purls: purls:
- "pkg:npm/ip-address" - "pkg:npm/ip-address"