From b2d2959edc3402c62acd9a96b7032852f12a7568 Mon Sep 17 00:00:00 2001 From: Sameer Kankute Date: Thu, 12 Mar 2026 13:12:31 +0530 Subject: [PATCH] Fix security tests --- ci_cd/security_scans.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/ci_cd/security_scans.sh b/ci_cd/security_scans.sh index 62440d13ebb..d1dc8f99d28 100755 --- a/ci_cd/security_scans.sh +++ b/ci_cd/security_scans.sh @@ -163,6 +163,7 @@ run_grype_scans() { "CVE-2026-25639" # axios - full fix requires 1.x major version bump; pinned to >=0.30.2 to clear other axios CVEs, upgrade to 1.x in follow-up "CVE-2026-2297" # Python 3.13 SourcelessFileLoader audit hook bypass - no fix available in base image "GHSA-qffp-2rhf-9h96" # tar hardlink path traversal - from nodejs_wheel bundled npm, not used in application runtime code + "GHSA-9ppj-qmqm-q256" # tar symlink path traversal - tracked in npm tooling paths in image scan; allowlisted to unblock CI until base/npm dependency graph fully converges on >=7.5.11 ) # Build JSON array of allowlisted CVE IDs for jq