mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
Reduces the container-image CVE surface flagged by Trivy. Genuinely fixed on every rebuild: - apt-get upgrade in the production stage pulls Ubuntu security patches for base-image packages (libgnutls30t64 3.8.3-1.1ubuntu3.5 -> ubuntu3.6, libgcrypt20, liblzma5), closing ~15 OS-package CVEs. - pip 25.1.1 -> 26.1.2 closes 4 pip CVEs (CVE-2025-8869, 2026-1703, 2026-3219, 2026-6357). Accepted via .trivyignore (canonical, reviewed): - 6 newly surfaced pnpm 9.x build-tool CVEs (fixed only in pnpm 10.x, a major migration tracked separately; pnpm runs at install/start only). - caire's bundled golang.org/x/image (esimov/caire v1.5.0 is latest and still pins x/image v0.18.0; no upstream fix). - brace-expansion 2.x ReDoS (transitive of glob; patched 5.0.6 already present; not reachable from user input). Already resolved in the current tree (clear on next scan): picomatch 4.0.4 (override), ip-address removed. Verification note: the Trivy job in release.yml depends on the intentionally gated-off docker build/publish job, so these cannot be re-scanned in CI without enabling image publishing. The image is not currently shipped.