mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-27 01:22:18 +00:00
Wolfi's security database names zlib 1.3.3-r0 as the fix for CVE-2026-85091, but the newest zlib published to the Wolfi apk repo is 1.3.2-r7. Every wolfi-base digest, including the current latest, still reports the CVE, so no base image bump or apk upgrade can clear it and image-scan fails on every PR touching a Dockerfile or the lockfile, and on the nightly schedule. Ignore that CVE and its GHSA alias for the zlib apk package only, so a fixable High in anything else still fails the job.
13 lines
465 B
YAML
13 lines
465 B
YAML
# Wolfi's security database names zlib 1.3.3-r0 as the fix for CVE-2026-85091,
|
|
# but the newest zlib published to the Wolfi apk repo is 1.3.2-r7, so every
|
|
# wolfi-base digest reports it and no `apk upgrade` can clear it.
|
|
# Drop this once Wolfi ships zlib >= 1.3.3-r0; expected by 2026-10-15.
|
|
ignore:
|
|
- vulnerability: CVE-2026-85091
|
|
package:
|
|
name: zlib
|
|
type: apk
|
|
- vulnerability: GHSA-g5fp-32jq-cfw2
|
|
package:
|
|
name: zlib
|
|
type: apk
|