Reduces the container-image CVE surface flagged by Trivy.
Genuinely fixed on every rebuild:
- apt-get upgrade in the production stage pulls Ubuntu security patches
for base-image packages (libgnutls30t64 3.8.3-1.1ubuntu3.5 -> ubuntu3.6,
libgcrypt20, liblzma5), closing ~15 OS-package CVEs.
- pip 25.1.1 -> 26.1.2 closes 4 pip CVEs (CVE-2025-8869, 2026-1703,
2026-3219, 2026-6357).
Accepted via .trivyignore (canonical, reviewed):
- 6 newly surfaced pnpm 9.x build-tool CVEs (fixed only in pnpm 10.x, a
major migration tracked separately; pnpm runs at install/start only).
- caire's bundled golang.org/x/image (esimov/caire v1.5.0 is latest and
still pins x/image v0.18.0; no upstream fix).
- brace-expansion 2.x ReDoS (transitive of glob; patched 5.0.6 already
present; not reachable from user input).
Already resolved in the current tree (clear on next scan): picomatch
4.0.4 (override), ip-address removed.
Verification note: the Trivy job in release.yml depends on the
intentionally gated-off docker build/publish job, so these cannot be
re-scanned in CI without enabling image publishing. The image is not
currently shipped.
All 13 HIGH CVEs (glob, minimatch, picomatch, tar) are bundled
inside pnpm 9.x itself, not in our application dependencies.
pnpm overrides only affect our app's dependency tree, not pnpm's
internal modules. All require upgrading to pnpm 10.x.