mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-16 23:41:43 +00:00
Wolfi's security database names zlib 1.3.3-r0 as the fix for CVE-2026-85091, but the newest zlib published to the Wolfi apk repo is 1.3.2-r7. Every wolfi-base digest, including the current latest, still reports the CVE, so no base image bump or apk upgrade can clear it and image-scan fails on every PR touching a Dockerfile or the lockfile, and on the nightly schedule. Ignore that CVE and its GHSA alias for the zlib apk package only, so a fixable High in anything else still fails the job. |
||
|---|---|---|
| .. | ||
| actions | ||
| codeql | ||
| e2e-stack | ||
| ISSUE_TEMPLATE | ||
| observatory | ||
| screenshots | ||
| scripts | ||
| workflows | ||
| ci-coverage-allowlist.yml | ||
| CODEOWNERS | ||
| dependabot.yaml | ||
| deploy-on-aws.png | ||
| deploy-on-gcp.png | ||
| deploy-to-aws.png | ||
| FUNDING.yml | ||
| mutmut-coverage.rc | ||
| pull_request_template.md | ||
| template.yaml | ||