Skip to content

Report unfixed high and critical image vulnerabilities - #236

Closed
RonaldHensbergen wants to merge 3 commits into
mainfrom
security/ignore-unfixed-false
Closed

Report unfixed high and critical image vulnerabilities#236
RonaldHensbergen wants to merge 3 commits into
mainfrom
security/ignore-unfixed-false

Conversation

@RonaldHensbergen

Copy link
Copy Markdown
Owner

Summary

  • stop suppressing unfixed vulnerabilities in the Trivy image scan
  • make HIGH and CRITICAL findings visible regardless of fix availability
  • establish the visibility required for reviewed VEX exceptions instead of implicit suppression

Behavior change

Unfixed HIGH or CRITICAL findings now fail the image-security job until they are remediated or handled through an explicit, reviewed exception process. This intentionally exposes findings such as CVE-2026-12087 that Docker Scout reports but the previous Trivy configuration hid.

Dependency

Depends on #235 because this branch was created from packaging/testpypi-cli. After #235 merges, this PR's diff will narrow to the Trivy configuration change.

RonaldHensbergen and others added 3 commits July 25, 2026 20:19
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@RonaldHensbergen

Copy link
Copy Markdown
Owner Author

Too much effort at this time

@RonaldHensbergen
RonaldHensbergen deleted the security/ignore-unfixed-false branch July 25, 2026 21:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant