Skip to content

UID2-7582: remove expired .trivyignore suppressions (CVE-2026-54512, CVE-2026-54513) - #2670

Merged
cYKatherine merged 1 commit into
mainfrom
kchen-UID2-7582-trivyignore-cleanup
Jul 28, 2026
Merged

UID2-7582: remove expired .trivyignore suppressions (CVE-2026-54512, CVE-2026-54513)#2670
cYKatherine merged 1 commit into
mainfrom
kchen-UID2-7582-trivyignore-cleanup

Conversation

@cYKatherine

Copy link
Copy Markdown
Contributor

Summary

Removes two .trivyignore suppressions that expired on 2026-07-25 (3 days ago).

CVE Package Expiry Original ticket
CVE-2026-54512 jackson-databind 2026-07-25 UID2-7364
CVE-2026-54513 jackson-databind 2026-07-25 UID2-7364

Why this is safe

Trivy stops honouring a suppression once its exp: date passes, so these lines have had no effect since 2026-07-25. The scheduled vulnerability scan on 2026-07-28 (00:41:51Z) passed with both entries already inert, which confirms neither CVE is being reported any more.

The suppressions were always intended as a stopgap — the comment noted the real fix was tracked in uid2-shared#631 and would 'flow here on the next uid2-shared release'. That has now happened, so the stopgap can go.

Found by the automated .trivyignore expiry audit. Jira: UID2-7582

🤖 Generated with Claude Code

…VE-2026-54513

Both jackson-databind suppressions expired 2026-07-25, so Trivy has not been
honouring them. The jackson bump has since flowed through from uid2-shared and
the 2026-07-28 scheduled scan passed with the entries already inert, confirming
neither CVE is reported any more.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@cYKatherine
cYKatherine merged commit e166540 into main Jul 28, 2026
10 checks passed
@cYKatherine
cYKatherine deleted the kchen-UID2-7582-trivyignore-cleanup branch July 28, 2026 01:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants