37bf443e29
The existing .grype.yaml ignore listed the wish SCP traversal only by CVE id; grype's db now matches it as GHSA-xjvp-7243-rg9h and ignores are exact-id, so the rc.2 scan gate tripped on an already-triaged finding. List both ids. Vulnerable SCP middleware is never compiled in; real fix is the charm v2 stack migration (#126). cliff.toml ignore_tags folds rc tags into the next real release so v0.1.0's notes cover full history instead of commits-since-rc.2.
12 lines
658 B
YAML
12 lines
658 B
YAML
ignore:
|
|
# SCP path traversal in charmbracelet/wish — same flaw, two ids: grype has
|
|
# matched it as CVE-2026-41589 and as GHSA-xjvp-7243-rg9h depending on db
|
|
# version, and ignore matching is exact-id, so both stay listed.
|
|
# We only import wish/bubbletea for the SSH TUI server — the vulnerable
|
|
# scp.Middleware / scp.NewFileSystemHandler symbols are never compiled in
|
|
# (govulncheck reachability agrees). No fix for wish v1; v2
|
|
# (charm.land/wish/v2 >= 2.0.1) requires the bubbletea-v2 stack migration,
|
|
# tracked in issue #126. Remove both entries when that lands.
|
|
- vulnerability: CVE-2026-41589
|
|
- vulnerability: GHSA-xjvp-7243-rg9h
|