Skip to content

more ignores of the same type of thing#1658

Merged
jabrown85 merged 1 commit into
mainfrom
jab/ignore-docker-cp-cves
May 29, 2026
Merged

more ignores of the same type of thing#1658
jabrown85 merged 1 commit into
mainfrom
jab/ignore-docker-cp-cves

Conversation

@jabrown85
Copy link
Copy Markdown
Contributor

Summary

This pull request updates the .grype.yaml configuration to ignore two additional Docker-related vulnerabilities that are not exploitable in the current usage context.

Security configuration updates:

  • Added GHSA-rg2x-37c3-w2rh (docker cp bind mount redirection race) and GHSA-x86f-5xw2-fm2r (daemon-side PUT /containers/{id}/archive RCE) to the ignore list, with comments explaining why these are not exploitable in this project. (.grype.yaml)

Signed-off-by: Jesse Brown <jabrown85@gmail.com>
@jabrown85 jabrown85 requested a review from a team as a code owner May 29, 2026 15:20
@jabrown85 jabrown85 enabled auto-merge May 29, 2026 15:20
@jabrown85 jabrown85 merged commit e2dc621 into main May 29, 2026
6 checks passed
@jabrown85 jabrown85 deleted the jab/ignore-docker-cp-cves branch May 29, 2026 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants