ci: suppress GHSA-r277-6w6q-xmqw via .trivyignore #2

Merged
onlyati merged 1 commit from ci/trivyignore-kin-openapi into main 2026-09-11 18:51:03 +00:00
Owner

getkin/kin-openapi v0.142.0 is flagged for GHSA-r277-6w6q-xmqw (CVSS
9.1, auth-bypass in openapi3filter.ValidationHandler). It is not a
runtime dependency of this project: it's pulled in solely as a
build-time dependency of the oapi-codegen tool (go.mod tool
directive; confirmed via go mod why -m github.com/getkin/kin-openapi),
used only to parse openapi.yaml during go generate. This project
never imports kin-openapi itself and never uses ValidationHandler (id
validation in server.go is a hand-written regex), so the vulnerable
code path is never linked into or reachable in the artifact-store
binary.

Verified with trivy fs .: the finding is suppressed and no longer
appears in the report.

Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01TgSQ9qFbc3Q1SwYaLzPT7i

getkin/kin-openapi v0.142.0 is flagged for GHSA-r277-6w6q-xmqw (CVSS 9.1, auth-bypass in openapi3filter.ValidationHandler). It is not a runtime dependency of this project: it's pulled in solely as a build-time dependency of the oapi-codegen tool (go.mod `tool` directive; confirmed via `go mod why -m github.com/getkin/kin-openapi`), used only to parse openapi.yaml during `go generate`. This project never imports kin-openapi itself and never uses ValidationHandler (id validation in server.go is a hand-written regex), so the vulnerable code path is never linked into or reachable in the artifact-store binary. Verified with `trivy fs .`: the finding is suppressed and no longer appears in the report. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TgSQ9qFbc3Q1SwYaLzPT7i
ci: suppress GHSA-r277-6w6q-xmqw via .trivyignore
All checks were successful
ci/woodpecker/pr/pr_check Pipeline was successful
ci/woodpecker/pr/ci Pipeline was successful
73dfc5b6cd
getkin/kin-openapi v0.142.0 is flagged for GHSA-r277-6w6q-xmqw (CVSS
9.1, auth-bypass in openapi3filter.ValidationHandler). It is not a
runtime dependency of this project: it's pulled in solely as a
build-time dependency of the oapi-codegen tool (go.mod `tool`
directive; confirmed via `go mod why -m github.com/getkin/kin-openapi`),
used only to parse openapi.yaml during `go generate`. This project
never imports kin-openapi itself and never uses ValidationHandler (id
validation in server.go is a hand-written regex), so the vulnerable
code path is never linked into or reachable in the artifact-store
binary.

Verified with `trivy fs .`: the finding is suppressed and no longer
appears in the report.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TgSQ9qFbc3Q1SwYaLzPT7i
onlyati deleted branch ci/trivyignore-kin-openapi 2026-09-11 18:51:03 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
pandora/artifact-store.goapp!2
No description provided.