mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
The Trivy scan finds HIGH CVEs in pnpm's own transitive dependencies (glob, minimatch, tar, picomatch) which are build-time only and not in the runtime image. These block manifest creation unnecessarily. Scan results still upload to GitHub Security tab via SARIF.