Commit 23a6263
UID2-6704: Suppress CVE-2026-22184 (zlib untgz) in .trivyignore
The vulnerability is in zlib's contrib/untgz demo utility, not the core
libz library. Alpine does not ship the untgz binary, and the JRE only
uses libz for compression. The zlib maintainer disputes this CVE and
removed the untgz tool entirely. Not exploitable in our context.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>1 parent 881cc91 commit 23a6263
1 file changed
Lines changed: 6 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
0 commit comments