Commit 539938e
chore: ignore CVE-2026-41305 (postcss build-time XSS) in Trivy (#1288)
postcss is a build-time-only dependency; we do not stringify untrusted
CSS ASTs at runtime, so the </style> stringify XSS is not exploitable.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent 07a5bb1 commit 539938e
1 file changed
Lines changed: 10 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
0 commit comments