Merge pull request #19587 from BerriAI/litellm_cicd_fix_yj_016

[Infra] CI/CD - Adding lodash-es to allowlist
This commit is contained in:
yuneng-jiang 2026-01-22 11:46:25 -08:00 • committed by GitHub
commit 01f355be7c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -138,6 +138,7 @@ run_grype_scans() {
"CVE-2026-22184" # zlib untgz buffer overflow - untgz unused + no fixed Wolfi build yet
"GHSA-58pv-8j8x-9vj2" # jaraco.context path traversal - setuptools vendored only (v5.3.0), not used in application code (using v6.1.0+)
"GHSA-r6q2-hw4h-h46w" # node-tar not used by application runtime, Linux-only container, not affect by macOS APFS-specific exploit
"CVE-2025-13465" # lodash-es is found in the docs dependencies, not used in application code
)
# Build JSON array of allowlisted CVE IDs for jq