Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review grype configuration #1778

Open
samayer12 opened this issue Feb 7, 2025 · 0 comments
Open

Review grype configuration #1778

samayer12 opened this issue Feb 7, 2025 · 0 comments
Labels
dependencies Pull requests that update a dependency file Github Actions Pull requests that update GitHub Actions code

Comments

@samayer12
Copy link
Contributor

#1777 created a temporary suppression to unblock CI while we await an upstream fix in libc6. This issue exists so that we don't forget to remove the suppression.

@samayer12 samayer12 added dependencies Pull requests that update a dependency file Github Actions Pull requests that update GitHub Actions code labels Feb 7, 2025
github-merge-queue bot pushed a commit that referenced this issue Feb 7, 2025
## Description

CVE-2025-0395 flagged in our upstream container images an causes CI to
fail. While we wait on a fix, we've opted to ignore this finding so that
CI pipelines are unblocked. We'll remove this suppression within 60 days
(see #1778).

End to End Test:  <!-- if applicable -->  
(See [Pepr Excellent
Examples](https://github.com/defenseunicorns/pepr-excellent-examples))

## Related Issue

hotfix

## Type of change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Other (security config, docs update, etc)

## Checklist before merging
- [x] Unit,
[Journey](https://github.com/defenseunicorns/pepr/tree/main/journey),
[E2E Tests](https://github.com/defenseunicorns/pepr-excellent-examples),
[docs](https://github.com/defenseunicorns/pepr/tree/main/docs),
[adr](https://github.com/defenseunicorns/pepr/tree/main/adr) added or
updated as needed
- [x] [Contributor Guide
Steps](https://docs.pepr.dev/main/contribute/#submitting-a-pull-request)
followed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file Github Actions Pull requests that update GitHub Actions code
Projects
Status: 🆕 New
Development

No branches or pull requests

1 participant