ci(image-scan): ignore zlib CVE-2026-85091 until Wolfi ships zlib 1.3.3-r0

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
jesus 2026-09-15 20:26:28 +00:00
parent 7d3917dbf4
commit 3156f2928a
2 changed files with 13 additions and 0 deletions

View file

@ -26,6 +26,7 @@ on:
- ui/Dockerfile
- ui/nginx.conf
- .github/workflows/image-scan.yml
- .grype.yaml
schedule:
- cron: "41 6 * * *"
workflow_dispatch:

12
.grype.yaml Normal file
View file

@ -0,0 +1,12 @@
# Wolfi's secdb says this zlib CVE is fixed in 1.3.3-r0, but the newest zlib
# published to the Wolfi/Chainguard apk repo is 1.3.2-r7, so even a fully
# upgraded wolfi-base reports it. Remove once apk upgrade pulls zlib >= 1.3.3-r0
ignore:
- vulnerability: CVE-2026-85091
package:
name: zlib
type: apk
- vulnerability: GHSA-g5fp-32jq-cfw2
package:
name: zlib
type: apk