diff --git a/.trivyignore b/.trivyignore index 3511344..1827137 100644 --- a/.trivyignore +++ b/.trivyignore @@ -31,7 +31,12 @@ CVE-2026-2100 exp:2026-09-01 # See: UID2-7456 CVE-2026-56131 exp:2026-08-09 CVE-2026-56407 exp:2026-08-09 -CVE-2026-56408 exp:2026-08-09 +# CVE-2026-56408 — libexpat (Alpine base image, transitive via eclipse-temurin:21-jre- +# alpine-3.23) (HIGH). +# Not exploitable here: Same eclipse-temurin alpine base; libexpat transitive only. No +# expat/XML_Parse/JNI references in source; JVM handles all XML parsing. +# See: UID2-7656 +CVE-2026-56408 exp:2026-11-11 # jackson-core async parser maxNumberLength bypass (GHSA-r7wm-3cxj-wff9) - incomplete fix for # GHSA-72hv-8253-57qq. Not exploitable: services only use the synchronous ObjectMapper API, not