mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
129 lines
5.6 KiB
YAML
129 lines
5.6 KiB
YAML
# Findings excluded from the Grype gate, each with a reason.
|
|
# Anything not listed here blocks the pull request at critical or high severity.
|
|
# Pairs are explicit: a new CVE against an already-listed package still blocks.
|
|
#
|
|
# Every entry below has a published fix we cannot take. Findings with no fix at all are
|
|
# not listed: the scan runs with only-fixed, so they never reach the gate.
|
|
|
|
ignore:
|
|
|
|
# Modules compiled into the Trivy binary we ship.
|
|
# Only a Trivy rebuild by its vendor can change these; the version is pinned in our Dockerfile.
|
|
# CVE-2026-71556 is the same temporary exception documented in .trivyignore.yaml:
|
|
# Trivy 0.73.0 still embeds go-git 5.19.1, while the 5.19.2 fix is merged only on
|
|
# Trivy main. Remove this entry with the Trivy exception by 2026-09-15.
|
|
# https://github.com/aquasecurity/trivy/blob/v0.73.0/go.mod#L46
|
|
# https://github.com/aquasecurity/trivy/commit/a2edba9a03987ba0d2ebc8212c1a9a1e6979497b
|
|
- vulnerability: CVE-2026-71556
|
|
package:
|
|
name: github.com/go-git/go-git/v5
|
|
# CVE-2026-84304 is the same temporary exception documented in .trivyignore.yaml:
|
|
# Trivy 0.74.0 still embeds grpc 1.82.1, while the 1.83.1 fix is not in any release.
|
|
# Prowler only runs `trivy image` / `trivy fs`, never client/server mode, so no gRPC
|
|
# endpoint exists in the image. Pinned to the embedded version so the rule stops
|
|
# matching on its own once Trivy bumps grpc. Remove with the Trivy exception by 2026-10-15.
|
|
# https://github.com/aquasecurity/trivy/pull/11176
|
|
- vulnerability: CVE-2026-84304
|
|
package:
|
|
name: google.golang.org/grpc
|
|
version: v1.82.1
|
|
# CVE-2026-84445 is the same temporary exception documented in .trivyignore.yaml:
|
|
# Trivy 0.74.0 still embeds grpc 1.82.1, while the 1.82.2 / 1.83.2 fix is not in any
|
|
# release. The panic needs a gRPC server built with `xds.NewGRPCServer()`; Prowler only
|
|
# runs `trivy image` / `trivy fs`, so the image serves no gRPC at all. Pinned to the
|
|
# embedded version so the rule stops matching on its own once Trivy bumps grpc. Remove
|
|
# with the Trivy exception by 2026-10-15.
|
|
# https://github.com/advisories/GHSA-2v4p-qf9q-27wj
|
|
- vulnerability: CVE-2026-84445
|
|
package:
|
|
name: google.golang.org/grpc
|
|
version: v1.82.1
|
|
# CVE-2026-56855 / CVE-2026-78662 are the same temporary exception documented in
|
|
# .trivyignore.yaml: Trivy 0.74.0 still embeds golang.org/x/crypto v0.55.0, while the
|
|
# 0.56.0 fix (published 2026-09-02) hasn't reached any Trivy release, or even Trivy
|
|
# main, yet. Pinned to the embedded version so the rule stops matching on its own once
|
|
# Trivy bumps it. Remove with the Trivy exception by 2026-10-15.
|
|
- vulnerability: CVE-2026-56855
|
|
package:
|
|
name: golang.org/x/crypto
|
|
version: v0.55.0
|
|
- vulnerability: CVE-2026-78662
|
|
package:
|
|
name: golang.org/x/crypto
|
|
version: v0.55.0
|
|
- vulnerability: CVE-2026-56852
|
|
package:
|
|
name: golang.org/x/text
|
|
- vulnerability: GHSA-hrxh-6v49-42gf
|
|
package:
|
|
name: google.golang.org/grpc
|
|
- vulnerability: CVE-2026-50151
|
|
package:
|
|
name: oras.land/oras-go/v2
|
|
|
|
# Shipped inside the PowerShell tarball, in its bundled MicrosoftTeams module.
|
|
# Not a dependency we declare, and not one we can upgrade independently.
|
|
- vulnerability: CVE-2026-26127
|
|
package:
|
|
name: Microsoft.Bcl.Memory
|
|
|
|
# The .NET runtime bundled inside the PowerShell tarball the Dockerfile pins.
|
|
# CVE-2026-62901 is the same temporary exception documented in .trivyignore.yaml:
|
|
# fixed in .NET 9.0.19 / 10.0.11 (2026-08-11), but no published PowerShell release
|
|
# ships a patched runtime yet (7.5.9 bundles 9.0.18; 7.6.4 bundles 10.0.x < 10.0.11).
|
|
# pwsh runs only local M365 module cmdlets; nothing listens for inbound WebSocket
|
|
# connections. Remove with the Trivy exception by 2026-09-15.
|
|
- vulnerability: CVE-2026-62901
|
|
package:
|
|
name: Microsoft.NETCore.App.Runtime.linux-x64
|
|
- vulnerability: CVE-2026-62901
|
|
package:
|
|
name: Microsoft.NETCore.App.Runtime.linux-arm64
|
|
|
|
|
|
# The CPython interpreter, compiled into the official base image.
|
|
# TEMPORARY, unlike the entries above: moving to Python 3.13 clears seven of these, and
|
|
# that is a runtime upgrade pending its own evaluation. The remaining three need 3.15 and
|
|
# are unfixable either way -- the MCP image already runs 3.13.14 and still reports them.
|
|
- vulnerability: CVE-2026-11940
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-11972
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-15308
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-3298
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-3644
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-4224
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-4786
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-6100
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-7210
|
|
package:
|
|
name: python
|
|
- vulnerability: CVE-2026-9669
|
|
package:
|
|
name: python
|
|
# CVE-2026-82049 (tarfile data/tar filter bypass via a hard link to a symlink) has no
|
|
# fixed CPython release on any branch: the fix is merged on main and 3.13 only, and the
|
|
# 3.12 backport is still open. Grype records 3.14.0b1 as the fix, so only-fixed does not
|
|
# drop it, yet python:3.12.14-slim-trixie reports it too. Prowler never extracts tar
|
|
# archives to disk: the ECR image inspection reads members in memory with extractfile().
|
|
# Remove once the base image ships a 3.12 release that includes the backport.
|
|
# https://github.com/python/cpython/issues/157190
|
|
# https://github.com/python/cpython/pull/157454
|
|
- vulnerability: CVE-2026-82049
|
|
package:
|
|
name: python
|