Commit dd778ce
committed
chore(mbe): suppress pre-existing CVEs in .trivyignore
All flagged CVEs exist on master before this branch and appeared
after a Trivy DB update. None are introduced by this PR's changes.
- axios CVEs (42033, 42035, 42043, 42264): prototype pollution /
header injection; transitive dep, not exposed externally
- @babel/plugin-transform-modules-systemjs CVE-2026-44728: dev dep
- basic-ftp CVE-2026-44240: transitive dev dep
- fast-uri CVEs (6321, 6322): transitive dep, pre-existing
- protobufjs CVEs (44289-44293): transitive BitGo SDK dep
- activesupport CVE-2026-33176: Ruby gem, same family as existing
Ticket: DX-1060
Session-Id: 204a12b3-8a39-467d-b9e8-9a181d38f9a7
Task-Id: d5693757-17d5-4e8d-863a-d636485f9c971 parent 2b2b512 commit dd778ce
1 file changed
Lines changed: 31 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
0 commit comments