Skip to content

Trivy ignore CVE-2026-84304 - #4714

Merged
ildyria merged 1 commit into
masterfrom
cve-2026-84304
Sep 3, 2026
Merged

Trivy ignore CVE-2026-84304#4714
ildyria merged 1 commit into
masterfrom
cve-2026-84304

Conversation

@ildyria

@ildyria ildyria commented Sep 3, 2026

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Chores
    • Updated vulnerability scanning exceptions for identified CVEs.
    • Documented that a fix is not currently available for one reported vulnerability in the runtime image.

@ildyria
ildyria requested a review from a team as a code owner September 3, 2026 10:39
@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The Trivy ignore configuration retains CVE-2026-56854 and adds CVE-2026-84304 with comments explaining the absence of a fix in the current FrankenPHP image.

Changes

Trivy Ignore Updates

Layer / File(s) Summary
Update ignored CVE entries
.trivyignore
The configuration retains the SSH-related CVE exclusion and adds the new CVE exclusion with explanatory comments.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: 🟡 Moderate · up to 6e717

The permanent ignore can hide a fixable vulnerability from future scans. Add an expiration and revalidate the pinned image digest before merging.

Poem

A rabbit checks the scanner’s trail
One CVE stays behind the rail
Another joins the list
With comments none can miss
FrankenPHP awaits a fix
While carrots guard the matrix mix

🚥 Pre-merge checks | ✅ 1
✅ Passed checks (1 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 1020c6fe-e2ac-4c95-8484-b9d4199912be

📥 Commits

Reviewing files that changed from the base of the PR and between 4a8bbe5 and 6e717b2.

📒 Files selected for processing (1)
  • .trivyignore

Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review.

Comment thread .trivyignore
@ildyria
ildyria merged commit 698d021 into master Sep 3, 2026
21 checks passed
@ildyria
ildyria deleted the cve-2026-84304 branch September 3, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant