Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 34 additions & 13 deletions .grype.yaml
Original file line number Diff line number Diff line change
@@ -1,26 +1,47 @@
scan-type: source
ignore:
- vulnerability: GHSA-5j98-mcp5-4vw2
include-aliases: true
reason: glob upgraded to 10.5.0 in package.json, but Node.js 22.20.0-alpine3.22 is still using glob 10.4.5
- vulnerability: CVE-2025-46394
reason: No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22
- vulnerability: CVE-2024-58251
reason: No fixes to busybox apk available as of 2025-10-16 on Dockerfile base image 22.20.0-alpine3.22
- vulnerability: CVE-2025-56200
include-aliases: true
reason: No fixes available as of 2025-10-16 on validator npm package
- vulnerability: CVE-2025-60876
include-aliases: true
reason: "Alpine base image package (apk): busybox - no npm fix available as of 2026-02-06 (moderate severity)"
- vulnerability: GHSA-34x7-hfp2-rc4v
include-aliases: true
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
reason: >-
tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application
dependency, no npm fix available as of 2026-02-10
- vulnerability: GHSA-r6q2-hw4h-h46w
include-aliases: true
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
reason: >-
tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application
dependency, no npm fix available as of 2026-02-10
- vulnerability: GHSA-8qq5-rm4j-mr97
include-aliases: true
reason: "tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application dependency, no npm fix available as of 2026-02-10"
reason: >-
tar 6.2.1/7.4.3 bundled inside npm in Node.js Docker image (node:22.22.0-alpine3.23) - not an application
dependency, no npm fix available as of 2026-02-10
- vulnerability: GHSA-3ppc-4f35-3m26
include-aliases: true
reason: >-
Base image npm package: minimatch - bundled in Node.js base image, not fixable via application dependencies as of
2026-02-23 (high severity)
- vulnerability: GHSA-83g3-92jg-28cx
include-aliases: true
reason: >-
Base image npm package: tar - bundled in Node.js base image, not fixable via application dependencies as of
2026-02-23 (high severity)
- vulnerability: GHSA-73rr-hh4g-fpgx
include-aliases: true
reason: >-
Base image npm package: diff - bundled in Node.js base image, not fixable via application dependencies as of
2026-02-23 (low severity)
- vulnerability: CVE-2026-27171
include-aliases: true
reason: "Alpine base image package (apk): zlib - no npm fix available as of 2026-02-23 (moderate severity)"
- vulnerability: GHSA-87r5-mp6g-5w5j
include-aliases: true
reason: "Unfixable npm transitive vulnerability: jsonpath (high severity) as of 2026-02-23"
- vulnerability: GHSA-2g4f-4pwh-qvx6
include-aliases: true
reason: "Unfixable npm transitive vulnerability: unknown (unknown severity) as of 2026-02-23"
output:
- table
- json
Expand Down
8 changes: 5 additions & 3 deletions audit-ci.jsonc
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,9 @@
// audit-ci supports reading JSON, JSONC, and JSON5 config files.
// Only use one of ["low": true, "moderate": true, "high": true, "critical": true]
"moderate": true,
"allowlist": [

"allowlist": [ // NOTE: Please add as much information as possible to any items added to the allowList
"GHSA-87r5-mp6g-5w5j",
"GHSA-2g4f-4pwh-qvx6",
"GHSA-3ppc-4f35-3m26" // minimatch ReDoS - fix requires v10 (major version break), unfixable via override
]
}
}
Loading