From 1785918d992acc1177565405197429c2b851d9c1 Mon Sep 17 00:00:00 2001 From: Neophytis <37024002+Neophytis@users.noreply.github.com> Date: Thu, 8 Oct 2026 22:44:42 +0200 Subject: [PATCH] chore(trivy): ignore CVE-2026-102633 until Alpine 3.24 ships libexpat 2.9.0 The fix (libexpat 2.9.0-r0) exists only in Alpine edge; 3.24-stable still ships 2.8.5-r0, so the daily apk refresh cannot pick it up and every image scan fails, which blocks the stage auto-deploy and the prod release job. Only git depends on libexpat in the image (PHP XML uses libxml2). --- .trivyignore | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.trivyignore b/.trivyignore index 5f2c6b6ea..d1ed1cf6b 100644 --- a/.trivyignore +++ b/.trivyignore @@ -3,3 +3,9 @@ # with a comment: package, fixed version, and when to remove the line. # The image refreshes apk packages daily (APK_REFRESH), so a fixed package is # picked up on the next day's build. + +# CVE-2026-102633: libexpat 2.8.5-r0; the fix (2.9.0-r0) is only in Alpine edge and not yet backported to Alpine 3.24. +# Only git depends on libexpat in the image (PHP XML uses libxml2), so exposure is minimal. +# Track: https://pkgs.alpinelinux.org/packages?name=libexpat&branch=v3.24 +# Remove once Alpine 3.24 ships libexpat >= 2.9.0-r0. +CVE-2026-102633