Skip to content

Commit

Permalink
trivy ignore pgx cve (#10142)
Browse files Browse the repository at this point in the history
  • Loading branch information
jenshu authored Oct 1, 2024
1 parent d4ab5d4 commit bf36897
Show file tree
Hide file tree
Showing 2 changed files with 13 additions and 3 deletions.
7 changes: 4 additions & 3 deletions .trivyignore
Original file line number Diff line number Diff line change
Expand Up @@ -54,10 +54,11 @@ CVE-2024-34156
# or later
CVE-2024-45258

# This CVE affects the packc/pgx dependency which is used in ext-auth-service
# These CVEs affect the packc/pgx dependency which is used in ext-auth-service
# The dependency is exclusively used in the monetization feature which we don't believe any customer uses and which is
# set to be deprecated
# Nevertheless the CVE has been addressed in the v1.15 LTS branch and later, however it is impractical to resolve in 1.14
# Nevertheless the CVEs have been addressed in the v1.15 LTS branch and later, however it is impractical to resolve in 1.14
# due to a number of other requisite dependency bumps
# Therefore we include this entry for now and should remove it once 1.14 is no longer an LTS branch
CVE-2024-27289
CVE-2024-27289
CVE-2024-27304
9 changes: 9 additions & 0 deletions changelog/v1.18.0-beta25/trivy-ignore-pgx.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
changelog:
- type: NON_USER_FACING
description: >-
Add CVE-2024-27304 to trivyignore as we are not planning on fixing in 1.14 and it does not impact Gateway
functionality.
skipCI-kube-tests:true
skipCI-storybook-tests:true
skipCI-docs-build:true

0 comments on commit bf36897

Please sign in to comment.