Skip to content

Commit 5402768

Browse files
ci(trivy): skip base Go binaries and ignore vulns in our CLIs
- Skip dockerd and docker-buildx (base image) via --skip-files/--skip-dirs - Add .trivyignore for dive, argo, kargo, pack, yq CVEs (exp 2026-08-19) Co-authored-by: Cursor <cursoragent@cursor.com>
1 parent def37af commit 5402768

File tree

3 files changed

+25
-0
lines changed

3 files changed

+25
-0
lines changed

.github/workflows/validate.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -94,6 +94,8 @@ jobs:
9494
--ignore-unfixed \
9595
--pkg-types library \
9696
--skip-dirs /home/runner/externals \
97+
--skip-dirs /usr/local/lib/docker \
98+
--skip-files /usr/bin/dockerd \
9799
--ignorefile .trivyignore \
98100
--severity HIGH,CRITICAL \
99101
--exit-code 1 \

.trivyignore

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,3 +31,24 @@ CVE-2025-61726 exp:2026-08-19
3131
CVE-2025-61728 exp:2026-08-19
3232
CVE-2025-61729 exp:2026-08-19
3333
CVE-2025-61730 exp:2026-08-19
34+
#
35+
# Go binaries we install (dive, argo, kargo, pack, yq); upgrade versions to clear
36+
CVE-2023-45288 exp:2026-08-19
37+
CVE-2024-24790 exp:2026-08-19
38+
CVE-2024-34156 exp:2026-08-19
39+
CVE-2024-41110 exp:2026-08-19
40+
CVE-2025-22868 exp:2026-08-19
41+
CVE-2025-22869 exp:2026-08-19
42+
CVE-2025-22874 exp:2026-08-19
43+
CVE-2025-29786 exp:2026-08-19
44+
CVE-2025-30204 exp:2026-08-19
45+
CVE-2025-32445 exp:2026-08-19
46+
CVE-2025-52881 exp:2026-08-19
47+
CVE-2025-59530 exp:2026-08-19
48+
CVE-2025-62156 exp:2026-08-19
49+
CVE-2025-62157 exp:2026-08-19
50+
CVE-2025-65637 exp:2026-08-19
51+
CVE-2025-66626 exp:2026-08-19
52+
CVE-2025-68156 exp:2026-08-19
53+
CVE-2026-23960 exp:2026-08-19
54+
CVE-2026-27112 exp:2026-08-19

scripts/builder.sh

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -292,6 +292,8 @@ trivy_scan () {
292292
--ignore-unfixed \
293293
--pkg-types library \
294294
--skip-dirs /home/runner/externals \
295+
--skip-dirs /usr/local/lib/docker \
296+
--skip-files /usr/bin/dockerd \
295297
--ignorefile .trivyignore \
296298
--input ${BUILD_DIR}/${IMAGE_NAME}-${IMAGE_TAG}.tar \
297299
--format github \

0 commit comments

Comments
 (0)