UID2-7582: remove expired .trivyignore suppressions (CVE-2026-54512, CVE-2026-54513) - #2670
Merged
Merged
Conversation
…VE-2026-54513 Both jackson-databind suppressions expired 2026-07-25, so Trivy has not been honouring them. The jackson bump has since flowed through from uid2-shared and the 2026-07-28 scheduled scan passed with the entries already inert, confirming neither CVE is reported any more. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
BehnamMozafari
approved these changes
Jul 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Removes two
.trivyignoresuppressions that expired on 2026-07-25 (3 days ago).Why this is safe
Trivy stops honouring a suppression once its
exp:date passes, so these lines have had no effect since 2026-07-25. The scheduled vulnerability scan on 2026-07-28 (00:41:51Z) passed with both entries already inert, which confirms neither CVE is being reported any more.The suppressions were always intended as a stopgap — the comment noted the real fix was tracked in uid2-shared#631 and would 'flow here on the next uid2-shared release'. That has now happened, so the stopgap can go.
Found by the automated
.trivyignoreexpiry audit. Jira: UID2-7582🤖 Generated with Claude Code