You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
- Add ignore-unfixed: true to Trivy workflow to focus on actionable vulnerabilities - Expand .trivyignore from 1 to 10 CVEs with detailed categorization - Document why each CVE is ignored (system libraries, unused features) - Ignore glibc/libtasn1 system library CVEs pending upstream fixes - Ignore curl CVEs for SSH/OAuth2/LDAP features not used by application - Ignore OpenLDAP CVE as library is not used by amcrest2mqtt This aligns with govee2mqtt security configuration and reduces noise from unfixable or non-applicable security alerts while maintaining focus on CRITICAL and HIGH severity issues that can be addressed. Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com> |
2 weeks ago | |
|---|---|---|
| .. | ||
| workflows | 2 weeks ago | |
| FUNDING.yml | 11 months ago | |
| SECURITY.md | 1 month ago | |
| dependabot.yml | 5 years ago | |