ci: suppress GHSA-r277-6w6q-xmqw via .trivyignore #2
Loading…
Reference in a new issue
No description provided.
Delete branch "ci/trivyignore-kin-openapi"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
getkin/kin-openapi v0.142.0 is flagged for GHSA-r277-6w6q-xmqw (CVSS
9.1, auth-bypass in openapi3filter.ValidationHandler). It is not a
runtime dependency of this project: it's pulled in solely as a
build-time dependency of the oapi-codegen tool (go.mod
tooldirective; confirmed via
go mod why -m github.com/getkin/kin-openapi),used only to parse openapi.yaml during
go generate. This projectnever imports kin-openapi itself and never uses ValidationHandler (id
validation in server.go is a hand-written regex), so the vulnerable
code path is never linked into or reachable in the artifact-store
binary.
Verified with
trivy fs .: the finding is suppressed and no longerappears in the report.
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01TgSQ9qFbc3Q1SwYaLzPT7i