Skip to content

ci(trivy): ignore CVE-2026-11940 until Alpine 3.24 backports python3 3.14.7-r0 - #483

Merged
Neophytis merged 1 commit into
feature/docker-betafrom
neophytis/ignore-cve-2026-11940
Aug 20, 2026
Merged

ci(trivy): ignore CVE-2026-11940 until Alpine 3.24 backports python3 3.14.7-r0#483
Neophytis merged 1 commit into
feature/docker-betafrom
neophytis/ignore-cve-2026-11940

Conversation

@Neophytis

Copy link
Copy Markdown
Contributor

CVE-2026-11940 (HIGH, tarfile filter bypass in cpython) is failing the Trivy scan. The fix version 3.14.7-r0 exists in Alpine edge but is not yet backported to the Alpine 3.24 repo that the image uses. The Dockerfile already runs apk upgrade at build time, so this will resolve automatically once 3.24 ships the fix. Track: https://pkgs.alpinelinux.org/packages?name=python3&branch=v3.24

@Neophytis

Copy link
Copy Markdown
Contributor Author

Applied directly to feature/docker-beta.

@Neophytis
Neophytis merged commit ad933bf into feature/docker-beta Aug 20, 2026
1 of 11 checks passed
@Neophytis
Neophytis deleted the neophytis/ignore-cve-2026-11940 branch August 20, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant