Skip to content

Commit a8d52c6

Browse files
committed
update .trivyignore
1 parent 00cf5fd commit a8d52c6

1 file changed

Lines changed: 21 additions & 0 deletions

File tree

src/node_24_python_3_14/.trivyignore.yaml

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,3 +19,24 @@ vulnerabilities:
1919
purls:
2020
- "pkg:pypi/wheel@0.45.1"
2121
expired_at: 2026-08-12
22+
- id: CVE-2025-64756
23+
statement: "glob: glob: Command Injection Vulnerability via Malicious Filenames"
24+
purls:
25+
- "pkg:npm/glob@10.4.5"
26+
- "pkg:npm/glob@11.0.3"
27+
expired_at: 2026-08-13
28+
- id: CVE-2026-23745
29+
statement: "node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives"
30+
purls:
31+
- "pkg:npm/tar@7.5.1"
32+
expired_at: 2026-08-13
33+
- id: CVE-2026-23950
34+
statement: "node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition"
35+
purls:
36+
- "pkg:npm/tar@7.5.1"
37+
expired_at: 2026-08-13
38+
- id: CVE-2026-24842
39+
statement: "node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check"
40+
purls:
41+
- "pkg:npm/tar@7.5.1"
42+
expired_at: 2026-08-13

0 commit comments

Comments
 (0)