Skip to content

fix(pipeline): fix DoS vulnerabilities & add trivyignore - #6

Merged
mello-sdn merged 4 commits into
mainfrom
fix/pipeline
Jun 27, 2026
Merged

mello-sdn merged 4 commits into
mainfrom
fix/pipeline

Conversation

@mello-sdn

Copy link
Copy Markdown
Owner
  • add .trivyignore for CVE-2026-12151 (undici) :
    This is an upstream issue from the Node base image (npm / node-gyp). The patch is still pending release on their side, and since this component isn't used by application in production, there is zero security risk

  • update nodemailer & multer (making DoS risk) to a fixed version

@mello-sdn
mello-sdn merged commit 43d8b3c into main Jun 27, 2026
5 checks passed
@mello-sdn mello-sdn changed the title Fix/pipeline fix(pipeline): fix DoS vulnerabilities & add trivyignore Jun 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant