fix(security): resolve 13 HIGH Trivy CVEs in npm dependencies

- Override glob>=10.5.0 (CVE-2025-64756 command injection)
- Override minimatch>=9.0.6 (CVE-2026-26996/27903/27904 ReDoS)
- Override tar>=7.5.11 (CVE-2026-23745/23950/24842/26960/29786/31802
  path traversal and arbitrary file overwrite)
- picomatch>=4.0.4 already overridden (CVE-2026-33671 ReDoS)
- Add .trivyignore for pnpm 9.x CVEs (CVE-2025-69262/69263) that
  require a major version bump to pnpm 10.x
- Restore Trivy as a blocking gate with trivyignore support
- Restore scan dependency in manifest job
This commit is contained in:
SnapOtter
2026-06-08 16:32:52 +08:00
parent 2c0a04c195
commit 012e2136ee
4 changed files with 22 additions and 11 deletions
+4 -9
View File
@@ -7,7 +7,10 @@ settings:
overrides:
fast-uri: '>=3.1.2'
handlebars: '>=4.7.9'
glob: '>=10.5.0'
minimatch: '>=9.0.6'
picomatch: '>=4.0.4'
tar: '>=7.5.11'
lodash: '>=4.18.0'
lodash-es: '>=4.18.0'
brace-expansion>minimatch: ^2.0.2
@@ -4856,10 +4859,6 @@ packages:
resolution: {integrity: sha512-MULkVLfKGYDFYejP07QOurDLLQpcjk7Fw+7jXS2R2czRQzR56yHRveU5NDJEOviH+hETZKSkIk5c+T23GjFUMg==}
engines: {node: 18 || 20 || >=22}
minimatch@5.1.9:
resolution: {integrity: sha512-7o1wEA2RyMP7Iu7GNba9vc0RWWGACJOCZBJX2GJWip0ikV+wcOsgVuY9uE8CPiyQhkGFSlhuSkZPavN7u1c2Fw==}
engines: {node: '>=10'}
minimatch@9.0.9:
resolution: {integrity: sha512-OBwBN9AL4dqmETlpS2zasx+vTeWclWzkblfZk7KTA5j3jeOONz/tRCnZomUyvNg83wL5Zv9Ss6HMJXAgL8R2Yg==}
engines: {node: '>=16 || 14 >=14.17'}
@@ -11105,10 +11104,6 @@ snapshots:
dependencies:
brace-expansion: 5.0.6
minimatch@5.1.9:
dependencies:
brace-expansion: 2.1.1
minimatch@9.0.9:
dependencies:
brace-expansion: 2.1.1
@@ -11720,7 +11715,7 @@ snapshots:
readdir-glob@1.1.3:
dependencies:
minimatch: 5.1.9
minimatch: 10.2.5
real-require@0.2.0: {}