Skip to content

chore: add CVE-2026-34986 to .trivyignore#3048

Merged
andyzhangx merged 3 commits intomasterfrom
fix/trivyignore-cve-2026-34986
Apr 5, 2026
Merged

chore: add CVE-2026-34986 to .trivyignore#3048
andyzhangx merged 3 commits intomasterfrom
fix/trivyignore-cve-2026-34986

Conversation

@andyzhangx
Copy link
Copy Markdown
Member

@andyzhangx andyzhangx commented Apr 5, 2026

Add CVE-2026-34986 to .trivyignore to unblock Trivy scan.

usr/local/bin/azcopy (gobinary)
===============================
Total: 1 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0)

┌───────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬────────────────────────────────────────────┐
│            Library            │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                   Title                    │
├───────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼────────────────────────────────────────────┤
│ github.com/go-jose/go-jose/v4 │ CVE-2026-34986 │ HIGH     │ fixed  │ v4.1.3            │ 4.1.4         │ Go JOSE Panics in JWE decryption           │
│                               │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-34986 │
└───────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴──────

@k8s-ci-robot
Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: andyzhangx

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Apr 5, 2026
@k8s-ci-robot k8s-ci-robot requested review from cvvz and gnufied April 5, 2026 02:04
@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. approved Indicates a PR has been approved by an approver from all required OWNERS files. labels Apr 5, 2026
@andyzhangx andyzhangx merged commit 38dce2c into master Apr 5, 2026
21 of 28 checks passed
@andyzhangx
Copy link
Copy Markdown
Member Author

/cherrypick release-1.35

@andyzhangx
Copy link
Copy Markdown
Member Author

/cherrypick release-1.34

@andyzhangx
Copy link
Copy Markdown
Member Author

/cherrypick release-1.33

@k8s-infra-cherrypick-robot
Copy link
Copy Markdown

@andyzhangx: new pull request created: #3050

Details

In response to this:

/cherrypick release-1.35

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@k8s-infra-cherrypick-robot
Copy link
Copy Markdown

@andyzhangx: #3048 failed to apply on top of branch "release-1.33":

Applying: chore: add CVE-2026-34986 to .trivyignore
Using index info to reconstruct a base tree...
M	.trivyignore
Falling back to patching base and 3-way merge...
Auto-merging .trivyignore
Applying: chore: remove fixed CVE-2026-25679 and CVE-2026-27142 from .trivyignore
Using index info to reconstruct a base tree...
M	.trivyignore
Falling back to patching base and 3-way merge...
Auto-merging .trivyignore
CONFLICT (content): Merge conflict in .trivyignore
error: Failed to merge in the changes.
hint: Use 'git am --show-current-patch=diff' to see the failed patch
hint: When you have resolved this problem, run "git am --continue".
hint: If you prefer to skip this patch, run "git am --skip" instead.
hint: To restore the original branch and stop patching, run "git am --abort".
hint: Disable this message with "git config set advice.mergeConflict false"
Patch failed at 0002 chore: remove fixed CVE-2026-25679 and CVE-2026-27142 from .trivyignore

Details

In response to this:

/cherrypick release-1.33

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@k8s-infra-cherrypick-robot
Copy link
Copy Markdown

@andyzhangx: new pull request created: #3051

Details

In response to this:

/cherrypick release-1.34

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants