Commit 360336c
UID2-6806: suppress CVE-2026-32776 (libexpat) in .trivyignore
libexpat NULL pointer dereference (CVE-2026-32776) - not exploitable as our
Java services do not use libexpat. Fix requires libexpat 2.7.5, not yet
available in eclipse-temurin Alpine 3.23. Also suppressing CVE-2026-32767
which is the same CVE with a Trivy typo (transposed digits).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 3178226 commit 360336c
1 file changed
Lines changed: 11 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
26 | | - | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
0 commit comments