diff --git a/.github/workflows/image-scan.yml b/.github/workflows/image-scan.yml index 206bb809e0c..c54f31ef1db 100644 --- a/.github/workflows/image-scan.yml +++ b/.github/workflows/image-scan.yml @@ -26,6 +26,7 @@ on: - ui/Dockerfile - ui/nginx.conf - .github/workflows/image-scan.yml + - .grype.yaml schedule: - cron: "41 6 * * *" workflow_dispatch: diff --git a/.grype.yaml b/.grype.yaml new file mode 100644 index 00000000000..7ec7e98080f --- /dev/null +++ b/.grype.yaml @@ -0,0 +1,12 @@ +# Wolfi's secdb says this zlib CVE is fixed in 1.3.3-r0, but the newest zlib +# published to the Wolfi/Chainguard apk repo is 1.3.2-r7, so even a fully +# upgraded wolfi-base reports it. Remove once apk upgrade pulls zlib >= 1.3.3-r0 +ignore: + - vulnerability: CVE-2026-85091 + package: + name: zlib + type: apk + - vulnerability: GHSA-g5fp-32jq-cfw2 + package: + name: zlib + type: apk