Skip to content

Commit 6469dbf

Browse files
authored
Merge pull request #2455 from dbinfrago/build/guacamole-trivy
build: Ignore irrelevant Guacamole CVEs
2 parents 789303f + 4f2fa90 commit 6469dbf

File tree

2 files changed

+13
-0
lines changed

2 files changed

+13
-0
lines changed

frontend/.trivyignore

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,3 +8,7 @@ CVE-2025-22869
88
# https://avd.aquasec.com/nvd/2025/cve-2025-22874/
99
# We don't use certificate validation in Caddy
1010
CVE-2025-22874
11+
12+
# https://github.com/golang/go/issues/74831
13+
# Caddy doesn't use any database
14+
CVE-2025-47907

images/guacamole/.trivyignore

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,3 +6,12 @@ CVE-2024-52046 exp:2025-09-01
66

77
# Wait for 1.6.0
88
CVE-2024-52316 exp:2025-09-01
9+
10+
# Write is not enabled in default tomcat servlet
11+
CVE-2025-24813
12+
CVE-2024-50379
13+
14+
# DoS attacks (ignored due to low risk; the application usually runs in isolated environments)
15+
CVE-2025-48988
16+
CVE-2024-34750
17+
CVE-2024-38286

0 commit comments

Comments
 (0)